bcgov / moh-keycloak-client-configurations

Apache License 2.0
1 stars 2 forks source link

update manage-users permissions #608

Closed filipflorek closed 1 month ago

filipflorek commented 1 month ago

Changes being made

Add bulk-removal role to Manage-Users realm role.

Context

On Keycloak DEV env, Manage-users is assigned to the am team and cgi dev team.

Quality Check

github-actions[bot] commented 1 month ago

Terraform Format and Style 🖌success

Terraform Initialization ⚙️success

Terraform Validation 🤖success

Terraform Plan 📖success

Show Plan ``` module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_SIT/CONSUMER"]: Refreshing state... [id=daf9d1e7-bea6-4eb7-9ce5-26ef14ee10e0/6578e80a-fbe5-4866-830d-76ac324c298c] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_STG/CONSUMER"]: Refreshing state... [id=daf9d1e7-bea6-4eb7-9ce5-26ef14ee10e0/4a4e1d44-f80f-4dc5-9c42-1d37c9aa16e9] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_CONF/CONSUMER"]: Refreshing state... [id=daf9d1e7-bea6-4eb7-9ce5-26ef14ee10e0/52caf85e-e771-4fa4-8274-1afc8d170cd2] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_REV/SECONDARY_SOURCE"]: Refreshing state... [id=29e820c6-284b-4209-ae0a-430c5033fd30/5438b8e8-4948-4446-a083-531ec9654913] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_FLVR/SECONDARY_SOURCE"]: Refreshing state... [id=29e820c6-284b-4209-ae0a-430c5033fd30/24124d3b-7a3e-4a8b-af90-47c03394b350] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_CONF/SECONDARY_SOURCE"]: Refreshing state... [id=29e820c6-284b-4209-ae0a-430c5033fd30/dcc3f917-a5aa-46f1-a7f7-3e9ed6e0e5ad] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_SIT/SECONDARY_SOURCE"]: Refreshing state... [id=29e820c6-284b-4209-ae0a-430c5033fd30/9c02e9eb-e774-4a31-8e43-3e54a54ea88f] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_UAT/SECONDARY_SOURCE"]: Refreshing state... [id=29e820c6-284b-4209-ae0a-430c5033fd30/7da1617b-2d92-4c2c-8981-dd7151a76a85] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_IAT/SECONDARY_SOURCE"]: Refreshing state... [id=29e820c6-284b-4209-ae0a-430c5033fd30/4e6fc50d-7fe8-4538-ac58-7871aea011b8] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_STG/SECONDARY_SOURCE"]: Refreshing state... [id=29e820c6-284b-4209-ae0a-430c5033fd30/f692dc45-2411-41f7-ac95-da948714f1a7] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_IAT/SECONDARY_SOURCE"]: Refreshing state... [id=moh_applications/client/a6111e23-097e-4f61-9c25-9343b0efd796/scope-mappings/a837283e-f96e-446d-9c51-5ac7d0eab773/4e6fc50d-7fe8-4538-ac58-7871aea011b8] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_STG/SECONDARY_SOURCE"]: Refreshing state... [id=moh_applications/client/a6111e23-097e-4f61-9c25-9343b0efd796/scope-mappings/2e161683-3c4d-4a2a-a86b-c83f2fe3e3d7/f692dc45-2411-41f7-ac95-da948714f1a7] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_UAT/SECONDARY_SOURCE"]: Refreshing state... [id=moh_applications/client/a6111e23-097e-4f61-9c25-9343b0efd796/scope-mappings/045f3224-9637-4785-a661-fc6f028804d2/7da1617b-2d92-4c2c-8981-dd7151a76a85] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_REV/SECONDARY_SOURCE"]: Refreshing state... [id=moh_applications/client/a6111e23-097e-4f61-9c25-9343b0efd796/scope-mappings/20e896f4-bf43-43ed-9441-d166e0513f34/5438b8e8-4948-4446-a083-531ec9654913] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_SIT/SECONDARY_SOURCE"]: Refreshing state... [id=moh_applications/client/a6111e23-097e-4f61-9c25-9343b0efd796/scope-mappings/1197df69-9199-49a5-a49a-c7d43d35551c/9c02e9eb-e774-4a31-8e43-3e54a54ea88f] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_CONF/SECONDARY_SOURCE"]: Refreshing state... [id=moh_applications/client/a6111e23-097e-4f61-9c25-9343b0efd796/scope-mappings/c0fe2e9f-6937-4ffa-9296-d786d9b0a98b/dcc3f917-a5aa-46f1-a7f7-3e9ed6e0e5ad] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-PRIMARY-CARE.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_FLVR/SECONDARY_SOURCE"]: Refreshing state... [id=moh_applications/client/a6111e23-097e-4f61-9c25-9343b0efd796/scope-mappings/ab63ae34-0fda-4f1b-ac8f-1380bea87f44/24124d3b-7a3e-4a8b-af90-47c03394b350] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_REV/CONSUMER"]: Refreshing state... [id=moh_applications/client/a7936745-ef13-4e97-a4a2-ef766867f1f4/scope-mappings/20e896f4-bf43-43ed-9441-d166e0513f34/d3dc70e8-af0e-4cb9-9e79-3706c94fd8da] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_SIT/CONSUMER"]: Refreshing state... [id=moh_applications/client/a7936745-ef13-4e97-a4a2-ef766867f1f4/scope-mappings/1197df69-9199-49a5-a49a-c7d43d35551c/6578e80a-fbe5-4866-830d-76ac324c298c] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_STG/CONSUMER"]: Refreshing state... [id=moh_applications/client/a7936745-ef13-4e97-a4a2-ef766867f1f4/scope-mappings/2e161683-3c4d-4a2a-a86b-c83f2fe3e3d7/4a4e1d44-f80f-4dc5-9c42-1d37c9aa16e9] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_CONF/CONSUMER"]: Refreshing state... [id=moh_applications/client/a7936745-ef13-4e97-a4a2-ef766867f1f4/scope-mappings/c0fe2e9f-6937-4ffa-9296-d786d9b0a98b/52caf85e-e771-4fa4-8274-1afc8d170cd2] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_UAT/CONSUMER"]: Refreshing state... [id=moh_applications/client/a7936745-ef13-4e97-a4a2-ef766867f1f4/scope-mappings/045f3224-9637-4785-a661-fc6f028804d2/d8799ef3-97b8-4f85-8f04-fb39cc8b813a] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_FLVR/CONSUMER"]: Refreshing state... [id=moh_applications/client/a7936745-ef13-4e97-a4a2-ef766867f1f4/scope-mappings/ab63ae34-0fda-4f1b-ac8f-1380bea87f44/055145d3-f83a-43ac-9b95-2161351f89c9] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-SHOPPERS.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PLR_IAT/CONSUMER"]: Refreshing state... [id=moh_applications/client/a7936745-ef13-4e97-a4a2-ef766867f1f4/scope-mappings/a837283e-f96e-446d-9c51-5ac7d0eab773/1251650d-4190-4cda-a00b-011cf1cbffc7] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-MOH-APPROVER.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_UAT/MOH_APPROVER"]: Refreshing state... [id=6b3b0e63-2bff-4f50-9e76-8bb40e3859cc/779c5ea7-5c9a-486f-ad8f-4fa2d1d8d365] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-MOH-APPROVER.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_CONF/MOH_APPROVER"]: Refreshing state... [id=6b3b0e63-2bff-4f50-9e76-8bb40e3859cc/37f6a73b-4640-412c-ac9f-ca9417b769f7] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-MOH-APPROVER.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_IAT/MOH_APPROVER"]: Refreshing state... [id=6b3b0e63-2bff-4f50-9e76-8bb40e3859cc/9aa82afd-7a6d-4dac-b5d6-033c12b36fa6] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-MOH-APPROVER.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_REV/MOH_APPROVER"]: Refreshing state... [id=6b3b0e63-2bff-4f50-9e76-8bb40e3859cc/0e63f5f5-a9b9-4b31-973c-2ecba829c3bb] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-MOH-APPROVER.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_SIT/MOH_APPROVER"]: Refreshing state... [id=6b3b0e63-2bff-4f50-9e76-8bb40e3859cc/a365f662-fbca-4c9a-af4b-076a860933a8] module.KEYCLOAK_PROD.module.moh_applications.module.DMFT-SERVICE.module.scope-mappings.keycloak_generic_client_role_mapper.SCOPE-MAPPING["PIDP-SERVICE/view_endorsement_data"]: Refreshing state... [id=moh_applications/client/c87f3feb-3c06-4d61-a5c2-48c593cccd1b/scope-mappings/c55eb420-fd84-41a8-b653-6e1b3e291519/0c2d08b1-b900-4b0c-a4d3-9e6e3e1ef847] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-PRIMARY-SOURCE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_SIT/PRIMARY_SOURCE"]: Refreshing state... [id=74af1232-8e9f-44e5-be27-0863f000291a/96650edd-ac15-4f9c-a27b-2be7231344bf] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-PRIMARY-SOURCE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_UAT/PRIMARY_SOURCE"]: Refreshing state... [id=74af1232-8e9f-44e5-be27-0863f000291a/9ce4e013-c2b7-4379-a46e-1c6b495803a6] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-PRIMARY-SOURCE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_REV/PRIMARY_SOURCE"]: Refreshing state... [id=74af1232-8e9f-44e5-be27-0863f000291a/4b919d71-c76b-4621-be50-f05a7e8ed144] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-PRIMARY-SOURCE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_IAT/PRIMARY_SOURCE"]: Refreshing state... [id=74af1232-8e9f-44e5-be27-0863f000291a/895c4a65-e67d-4657-bba3-df5a1440fc58] module.KEYCLOAK_TEST.module.moh_applications.module.PLR-QA-PRIMARY-SOURCE.module.service-account-roles.keycloak_openid_client_service_account_role.ROLE["PLR_CONF/PRIMARY_SOURCE"]: Refreshing state... [id=74af1232-8e9f-44e5-be27-0863f000291a/7430c88e-e4e4-4bbd-b262-d4c9bc3ba564] module.KEYCLOAK_DEV.module.moh_applications.module.CGI-DBA.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/9ada1d3b-be63-40a3-84f2-e4ec0e10be88] module.KEYCLOAK_PROD.module.moh_applications.module.MANAGE-USERS.keycloak_role.REALM_ROLE: Refreshing state... [id=eeac5c0a-7b1b-4607-ad95-1630769b5892] module.KEYCLOAK_DEV.module.moh_applications.module.CGI-AM-TEAM.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/053fa749-b569-4258-bc9e-bc8ca0541dfe] module.KEYCLOAK_DEV.module.moh_applications.module.CGI-MID-TIER.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/4e3d322a-fbe7-438d-8ee7-95a1707d40dc] module.KEYCLOAK_DEV.module.moh_applications.module.CGI-QA.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/1798203d-027f-4856-a445-8a90c1dc9756] module.KEYCLOAK_DEV.module.moh_applications.module.CGI-DEVELOPER.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/27967216-03f7-4259-b50a-955b995d51ad] module.KEYCLOAK_TEST.module.moh_applications.module.CGI-MIDTIER.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/782fe94e-79a2-438f-9bc1-28717395b28d] module.KEYCLOAK_TEST.module.moh_applications.module.CGI-QA.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/658f081c-a8b0-4c1b-b9ee-7e8901158ce7] module.KEYCLOAK_TEST.module.moh_applications.module.CGI-AM-TEAM.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/eb2dce73-6fe7-4b63-8b7a-c5995a530714] module.KEYCLOAK_TEST.module.moh_applications.module.CGI-DEVELOPER.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/ba2aead8-cd2d-4519-991b-3bd44c71c057] module.KEYCLOAK_PROD.module.moh_applications.module.CGI-AM-TEAM.keycloak_group_roles.GROUP_ROLES: Refreshing state... [id=moh_applications/270966e6-985c-4d55-a35c-53e32ab4cf46] Note: Objects have changed outside of Terraform Terraform detected the following changes made outside of Terraform since the last "terraform apply" which may have affected this plan: # module.KEYCLOAK_PROD.module.moh_applications.module.EDRD.module.client-roles.keycloak_role.ROLES["EDRD_Reviewers"] has changed ~ resource "keycloak_role" "ROLES" { + attributes = {} id = "0e055f82-ad87-4faf-9628-f9ca97ecbb95" name = "EDRD_Reviewers" # (2 unchanged attributes hidden) } # module.KEYCLOAK_TEST.module.moh_applications.module.EDRD.module.client-roles.keycloak_role.ROLES["EDRD_Reviewers"] has changed ~ resource "keycloak_role" "ROLES" { + attributes = {} id = "acc33369-338e-4a19-94a8-739c8c964697" name = "EDRD_Reviewers" # (2 unchanged attributes hidden) } Unless you have made equivalent changes to your configuration, or ignored the relevant attributes using ignore_changes, the following plan may include actions to undo or respond to these changes. ───────────────────────────────────────────────────────────────────────────── Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols: ~ update in-place Terraform will perform the following actions: # module.KEYCLOAK_DEV.module.moh_applications.module.MANAGE-USERS.keycloak_role.REALM_ROLE will be updated in-place ~ resource "keycloak_role" "REALM_ROLE" { ~ composite_roles = [ + "585f7572-a644-481d-92a7-b0ca8ad65cf4", # (26 unchanged elements hidden) ] ~ description = "Provides the roles required to manage users using the USER-MANAGEMENT application including roles for all applications. In DEV this role is provided to the Developer and Midtier teams." -> "Provides the roles required to manage users using the USER-MANAGEMENT application including roles for all applications. In DEV this role is provided to the Developer and AM teams." id = "8e526714-e19a-4760-b5e8-40efcb2c0b9c" name = "Manage Users" # (2 unchanged attributes hidden) } Plan: 0 to add, 1 to change, 0 to destroy. ───────────────────────────────────────────────────────────────────────────── Note: You didn't use the -out option to save this plan, so Terraform can't guarantee to take exactly these actions if you run "terraform apply" now. ```

Pushed by: @filipflorek, Action: pull_request