Closed mathieugravil closed 4 years ago
Thanks for the feedback! We are routing this to the appropriate team for follow-up. cc @Azure/aks-pm
@sauryadas anyone who can look at this key rotation issue from python SDK?
@zikalino @andyzhangx would you guys know?
@zikalino do you need more informations on this issue?
@mathieugravil have you tried azure cli az aks update-credentials --reset-service-principal ...
? does it work?
And you could refer to this for your code: https://github.com/Azure/azure-cli/blob/master/src/azure-cli/azure/cli/command_modules/acs/custom.py#L1907
@andyzhangx , I will try. I will keep you inform. Thanks
Hello @andyzhangx Sorry for the delay. Please find the test result : `$ az --version azure-cli 2.0.76 *
command-modules-nspkg 2.0.3 core 2.0.76 * nspkg 3.0.4 telemetry 1.0.4
Python location '/usr/bin/python' Extensions directory '/home/1V14713/.azure/cliextensions'
Python (Linux) 3.6.9 (default, Oct 17 2019, 11:10:22) [GCC 8.3.0]
Legal docs and information: aka.ms/AzureCliLegal
You have 2 updates available. Consider updating your CLI installation. $ az aks update-credentials -g rg-total-poc-we-apimgt -n APIMGT-POC-AKS --subscription "TOTAL DIVERS" --reset-service-principal --service-principal 7b64e0f5-dff9-4221-beac-44e1321b875e --client-secret 'LD6hpg7G7h@S9of=.:PkY@3BvDXkb@0h'
`
@andyzhangx any ideas?
@andyzhangx , I have mdea some complementary test: and it seems that the trouble is linked to the secret value/type: this works :
test = '2ZxeCDEHYddXAVtfyyLb9XEvTB1TwGeJ'
try:
K8sClient.managed_clusters.reset_service_principal_profile(resource_group_name, cluster_name, cluster.service_principal_profile.client_id,test)
but this not:
test = str(newKeyValueCluster)
try:
K8sClient.managed_clusters.reset_service_principal_profile(resource_group_name, cluster_name, cluster.service_principal_profile.client_id,test)
in newKeyValueCluster is a string I have generated from function... Any idea?
Hello @andyzhangx ,
My collegue find where is the trouble!!! In fact, first i create a new password key and after i use it to reset in cluster. It seems that i need to wait some time between the 2 actions whereas it failed....
Describe the bug A clear and concise description of what the bug is.
To Reproduce Steps to reproduce the behavior:
My test function :
And it failed :
Expected behavior I expect it reset spn of cluster and aad profile .
Screenshots If applicable, add screenshots to help explain your problem.
Additional context Add any other context about the problem here.