equinor / cc-components

Components and apps for CC.
MIT License
4 stars 0 forks source link

ci/sync admins #1053

Open Gustav-Eikaas opened 2 days ago

Gustav-Eikaas commented 2 days ago

Create an action that reads users from the Self service contributor group and adds them as admins in all fusion apps owned by the service principal we use for deploying.

SP needs a claim to be able to read the membership of the group. Looks like it needs Graph GroupMember.Read.All https://docs.omnia.equinor.com/governance/iam/App-Admin-Consent/#groupsreadall

Delays are absolutely necessary to avoid fusion api becoming unresponsive. Could still be an issue if the AD group has major changes in members