│ Error: waiting for service endpoint ready. Error looking up service endpoint given ID (ec3a329b-3110-4c04-9664-934fc14c9193) and project ID (6433a9cc-df1b-4f50-bf57-07437f64d9d3): map[severity:<nil> state:Failed statusMessage:TF14045: The identity with type 'Microsoft.VisualStudio.Services.Claims.AadServicePrincipal' could not be found.]
Expected Behavior
It should create the Azure DevOps Service Connection object, and then the Azure Entra Service Connection/App Reg
Actual Behavior
It creates the Azure DevOps Service Connection object
Whilst waiting for creation of the Azure Entra Service Connection/App Reg, after 20 seconds the error above appears.
The Azure DevOps Service Connection object exists but no Azure Entra Service Connection
Steps to Reproduce
Create a Workload Identity Federation (Automatic) service connection
Run TF apply
Important Factoids
The Service Connection that Terraform is running with has the following rights:
• Azure DevOps : Project Collection Administrator.
• Azure : "Application Developer" role, which allows it to create app registrations.
• Azure: User Access Admin rights on the subscription that the RG is in, so it can configure access permissions.
Service Connection that Terraform uses is able to create resources via the Azure CLI
Community Note
Terraform (and Azure DevOps Provider) Version
TF Version: v1.6.6 Azure DevOps Provider: 1.1.0
Affected Resource(s)
azuredevops_serviceendpoint_azurerm
Terraform Configuration Files
Panic Output
Expected Behavior
It should create the Azure DevOps Service Connection object, and then the Azure Entra Service Connection/App Reg
Actual Behavior
Steps to Reproduce
Important Factoids
References
0000