Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New Resources: azuread_application_registration, azuread_application_from_template and others #1214

Merged
merged 46 commits into from
Oct 20, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
46 commits
Select commit Hold shift + click to select a range
28dbbde
dependencies: updating to v0.64.0 of github.com/manicminer/hamilton
manicminer Oct 17, 2023
d2a1916
Deprecate some utils functions
manicminer Oct 17, 2023
5d14083
New Resource: `azuread_application_registration`
manicminer Oct 17, 2023
df0fe72
New Resource: `azuread_application_permission_scope`
manicminer Oct 17, 2023
58eae61
New Resource: `azuread_application_app_role`
manicminer Oct 17, 2023
00d782a
azuread_application_registration: support `homepage_url` and `logout_…
manicminer Oct 17, 2023
e5ceab8
fix up URL/URI validation
manicminer Oct 17, 2023
1eaef8b
New Resource: `azuread_application_fallback_public_client`
manicminer Oct 17, 2023
7e3d001
New Resource: `azuread_application_owner`
manicminer Oct 17, 2023
7092d33
New Resource: `azuread_application_identifier_uri`
manicminer Oct 17, 2023
a1ae108
Fix bug in new ID validators
manicminer Oct 17, 2023
d232e07
Fix up comments
manicminer Oct 17, 2023
2fca6ae
New Resource: `azuread_application_api_access`
manicminer Oct 17, 2023
c170ef9
New Resource: `azuread_application_known_clients`
manicminer Oct 17, 2023
f9fa8bc
azuread_application_registration: remove post-create patch, support `…
manicminer Oct 18, 2023
2b05bc6
azuread_application_registration: support `group_membership_claims`
manicminer Oct 18, 2023
21610c7
New Resource: `azuread_application_redirect_uris`
manicminer Oct 18, 2023
4e29ea8
New Resource: `azuread_application_from_template`
manicminer Oct 18, 2023
7e96eb4
azuread_application: export the `client_id` attribute
manicminer Oct 18, 2023
3a9766d
acceptance: fix up regex for ImportError
manicminer Oct 18, 2023
e67c84d
upgrade resource ID for azuread_application and support `application_…
manicminer Oct 18, 2023
51d4c6a
azuread_service_principal: support `client_id` and deprecate `applica…
manicminer Oct 18, 2023
f76b3f9
documentation for `azuread_application`, also export the `object_id` …
manicminer Oct 18, 2023
1e113e6
documentation for `azuread_application_api_access`
manicminer Oct 18, 2023
49265d1
documentation for `azuread_application_app_role`
manicminer Oct 18, 2023
dd96d9f
updated documentation for `azuread_application_certificate` and `azur…
manicminer Oct 18, 2023
1f6d2f9
updated documentation for `azuread_application_federated_identity_cre…
manicminer Oct 18, 2023
111a878
updated documentation for `azuread_application_pre_authorized_applica…
manicminer Oct 18, 2023
c97714b
updated documentation for `azuread_application` and `data.azuread_app…
manicminer Oct 18, 2023
9904ece
update golangci-lint
manicminer Oct 18, 2023
d346e54
documentation for `azuread_application_fallback_public_client`
manicminer Oct 19, 2023
89341b0
documentation for `azuread_application_from_template`
manicminer Oct 19, 2023
80b10c4
documentation for `azuread_application_identifier_uri`
manicminer Oct 19, 2023
38101d5
documentation for `azuread_application_known_clients`
manicminer Oct 19, 2023
0b5d422
documentation for `azuread_application_owner`
manicminer Oct 19, 2023
9e0d322
documentation for `azuread_application_permission_scope`
manicminer Oct 19, 2023
6fd38c5
add missing forcenew notes
manicminer Oct 19, 2023
6e321ab
documentation for `azuread_application_redirect_uris`, also add a tes…
manicminer Oct 19, 2023
20a10e4
updated docs for `azuread_service_principal`, `data.azuread_service_p…
manicminer Oct 19, 2023
2c0407d
linting!
manicminer Oct 19, 2023
8737b78
dependencies: updating to v0.20231018.1171511 of github.com/hashicorp…
manicminer Oct 19, 2023
24e1971
remove final usages and delete the utils package
manicminer Oct 19, 2023
f487c57
docs: update permissions for service principal resources
manicminer Oct 19, 2023
132386c
azuread_application test fixes
manicminer Oct 19, 2023
8d1a89b
goimports
manicminer Oct 19, 2023
bf00f05
address review, undocument deprecated properties
manicminer Oct 20, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/golint.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
go-version-file: .go-version
- uses: golangci/golangci-lint-action@3a919529898de77ec3da873e3063ca4b10e7f5cc # v3.7.0
with:
version: 'v1.50.1'
version: 'v1.54.2'
args: -v

save-artifacts-on-fail:
Expand Down
2 changes: 1 addition & 1 deletion GNUmakefile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ tools:
go install github.com/bflad/tfproviderdocs@latest
go install github.com/katbyte/terrafmt@latest
go install mvdan.cc/gofumpt@latest
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b "$$(go env GOPATH || $$GOPATH)"/bin v1.49.0
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b "$$(go env GOPATH || $$GOPATH)"/bin v1.54.2

build: fmtcheck
go install
Expand Down
8 changes: 4 additions & 4 deletions docs/data-sources/application.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,19 +22,19 @@ data "azuread_application" "example" {
}

output "application_object_id" {
value = data.azuread_application.example.id
value = data.azuread_application.example.object_id
}
```

## Argument Reference

The following arguments are supported:

* `application_id` - (Optional) Specifies the Application ID (also called Client ID).
* `client_id` - (Optional) Specifies the Client ID of the application.
* `display_name` - (Optional) Specifies the display name of the application.
* `object_id` - (Optional) Specifies the Object ID of the application.

~> One of `object_id`, `application_id` or `display_name` must be specified.
~> One of `client_id`, `display_name`, or `object_id` must be specified.

## Attributes Reference

Expand All @@ -43,7 +43,7 @@ The following attributes are exported:
* `api` - An `api` block as documented below.
* `app_role_ids` - A mapping of app role values to app role IDs, intended to be useful when referencing app roles in other resources in your configuration.
* `app_roles` - A collection of `app_role` blocks as documented below. For more information see [official documentation on Application Roles](https://docs.microsoft.com/en-us/azure/architecture/multitenant-identity/app-roles).
* `application_id` - The Application ID (also called Client ID).
* `client_id` - The Client ID for the application.
* `description` - A description of the application, as shown to end users.
* `device_only_auth_enabled` - Specifies whether this application supports device authentication without a user.
* `disabled_by_microsoft` - Whether Microsoft has disabled the registered application. If the application is disabled, this will be a string indicating the status/reason, e.g. `DisabledDueToViolationOfServicesAgreement`
Expand Down
4 changes: 2 additions & 2 deletions docs/data-sources/application_published_app_ids.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,15 +28,15 @@ output "published_app_ids" {
data "azuread_application_published_app_ids" "well_known" {}

resource "azuread_service_principal" "msgraph" {
application_id = data.azuread_application_published_app_ids.well_known.result.MicrosoftGraph
application_id = data.azuread_application_published_app_ids.well_known.result["MicrosoftGraph"]
use_existing = true
}

resource "azuread_application" "example" {
display_name = "example"

required_resource_access {
resource_app_id = data.azuread_application_published_app_ids.well_known.result.MicrosoftGraph
resource_app_id = data.azuread_application_published_app_ids.well_known.result["MicrosoftGraph"]

resource_access {
id = azuread_service_principal.msgraph.app_role_ids["User.Read.All"]
Expand Down
12 changes: 6 additions & 6 deletions docs/data-sources/service_principal.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,11 +24,11 @@ data "azuread_service_principal" "example" {
}
```

*Look up by application ID (client ID)*
*Look up by client ID*

```terraform
data "azuread_service_principal" "example" {
application_id = "00000000-0000-0000-0000-000000000000"
client_id = "00000000-0000-0000-0000-000000000000"
}
```

Expand All @@ -44,23 +44,23 @@ data "azuread_service_principal" "example" {

The following arguments are supported:

* `application_id` - (Optional) The application ID (client ID) of the application associated with this service principal.
* `client_id` - (Optional) The client ID of the application associated with this service principal.
* `display_name` - (Optional) The display name of the application associated with this service principal.
* `object_id` - (Optional) The object ID of the service principal.

~> One of `application_id`, `display_name` or `object_id` must be specified.
~> One of `client_id`, `display_name` or `object_id` must be specified.

## Attributes Reference

The following attributes are exported:

* `account_enabled` - Whether or not the service principal account is enabled.
* `account_enabled` - Whether the service principal account is enabled.
* `alternative_names` - A list of alternative names, used to retrieve service principals by subscription, identify resource group and full resource ids for managed identities.
* `application_id` - The application ID (client ID) of the application associated with this service principal.
* `app_role_assignment_required` - Whether this service principal requires an app role assignment to a user or group before Azure AD will issue a user or access token to the application.
* `app_role_ids` - A mapping of app role values to app role IDs, as published by the associated application, intended to be useful when referencing app roles in other resources in your configuration.
* `app_roles` - A list of app roles published by the associated application, as documented below. For more information [official documentation](https://docs.microsoft.com/en-us/azure/architecture/multitenant-identity/app-roles).
* `application_tenant_id` - The tenant ID where the associated application is registered.
* `client_id` - The client ID of the application associated with this service principal.
* `description` - A description of the service principal provided for internal end-users.
* `display_name` - The display name of the application associated with this service principal.
* `features` - A `features` block as described below.
Expand Down
13 changes: 7 additions & 6 deletions docs/data-sources/service_principals.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ data "azuread_service_principals" "example" {

```terraform
data "azuread_service_principals" "example" {
application_ids = [
client_ids = [
"11111111-0000-0000-0000-000000000000",
"22222222-0000-0000-0000-000000000000",
"33333333-0000-0000-0000-000000000000",
Expand All @@ -55,19 +55,20 @@ data "azuread_service_principals" "example" {

The following arguments are supported:

* `application_ids` - (Optional) A list of application IDs (client IDs) of the applications associated with the service principals.
* `client_ids` - (Optional) A list of client IDs of the applications associated with the service principals.
* `display_names` - (Optional) A list of display names of the applications associated with the service principals.
* `ignore_missing` - (Optional) Ignore missing service principals and return all service principals that are found. The data source will still fail if no service principals are found. Defaults to false.
* `object_ids` - (Optional) The object IDs of the service principals.
* `return_all` - (Optional) When `true`, the data source will return all service principals. Cannot be used with `ignore_missing`. Defaults to false.

~> Either `return_all`, or one of `application_ids`, `display_names` or `object_ids` must be specified. These _may_ be specified as an empty list, in which case no results will be returned.
~> Either `return_all`, or one of `client_ids`, `display_names` or `object_ids` must be specified. These _may_ be specified as an empty list, in which case no results will be returned.

## Attributes Reference

The following attributes are exported:

* `application_ids` - A list of application IDs (client IDs) of the applications associated with the service principals.
* `application_ids` - A list of client IDs of the applications associated with the service principals.
* `client_ids` - A list of client IDs of the applications associated with the service principals.
* `display_names` - A list of display names of the applications associated with the service principals.
* `object_ids` - The object IDs of the service principals.
* `service_principals` - A list of service principals. Each `service_principal` object provides the attributes documented below.
Expand All @@ -76,10 +77,10 @@ The following attributes are exported:

`service_principal` object exports the following:

* `account_enabled` - Whether or not the service principal account is enabled.
* `account_enabled` - Whether the service principal account is enabled.
* `app_role_assignment_required` - Whether this service principal requires an app role assignment to a user or group before Azure AD will issue a user or access token to the application.
* `application_id` - The application ID (client ID) of the application associated with this service principal.
* `application_tenant_id` - The tenant ID where the associated application is registered.
* `client_ids` - The client ID of the application associated with this service principal.
* `display_name` - The display name of the application associated with this service principal.
* `object_id` - The object ID of the service principal.
* `preferred_single_sign_on_mode` - The single sign-on mode configured for this application. Azure AD uses the preferred single sign-on mode to launch the application from Microsoft 365 or the Azure AD My Apps.
Expand Down
2 changes: 1 addition & 1 deletion docs/resources/access_package_catalog_role_assignment.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,5 +57,5 @@ In addition to all arguments above, the following attributes are exported:
Catalog role assignments can be imported using the ID of the assignment, e.g.

```shell
terraform import azuread_access_package_catalog_role_assignment.test 00000000-0000-0000-0000-000000000000
terraform import azuread_access_package_catalog_role_assignment.example 00000000-0000-0000-0000-000000000000
```
2 changes: 1 addition & 1 deletion docs/resources/administrative_unit_member.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ In addition to all arguments above, the following attributes are exported:
Administrative unit members can be imported using the object ID of the administrative unit and the object ID of the member, e.g.

```shell
terraform import azuread_administrative_unit_member.test 00000000-0000-0000-0000-000000000000/member/11111111-1111-1111-1111-111111111111
terraform import azuread_administrative_unit_member.example 00000000-0000-0000-0000-000000000000/member/11111111-1111-1111-1111-111111111111
```

-> This ID format is unique to Terraform and is composed of the Administrative Unit Object ID and the target Member Object ID in the format `{AdministrativeUnitObjectID}/member/{MemberObjectID}`.
2 changes: 1 addition & 1 deletion docs/resources/administrative_unit_role_member.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ In addition to all arguments above, the following attributes are exported:
Administrative unit role members can be imported using the object ID of the administrative unit and the unique ID of the role assignment, e.g.

```shell
terraform import azuread_administrative_unit_role_member.test 00000000-0000-0000-0000-000000000000/roleMember/zX37MRLyF0uvE-xf2WH4B7x-6CPLfudNnxFGj800htpBXqkxW7bITqGb6Rj4kuTuS
terraform import azuread_administrative_unit_role_member.example 00000000-0000-0000-0000-000000000000/roleMember/zX37MRLyF0uvE-xf2WH4B7x-6CPLfudNnxFGj800htpBXqkxW7bITqGb6Rj4kuTuS
```

-> This ID format is unique to Terraform and is composed of the Administrative Unit Object ID and the role assignment ID in the format `{AdministrativeUnitObjectID}/roleMember/{RoleAssignmentID}`.
17 changes: 12 additions & 5 deletions docs/resources/application.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,15 +6,19 @@ subcategory: "Applications"

Manages an application registration within Azure Active Directory.

For a more lightweight alternative, please see the [azuread_application_registration](application_registration.html) resource. Please note that this resource should not be used together with the `azuread_application_registration` resource when managing the same application.

## API Permissions

The following API permissions are required in order to use this resource.

When authenticated with a service principal, this resource requires the following application role: `Application.ReadWrite.All`
When authenticated with a service principal, this resource requires one of the following application roles: `Application.ReadWrite.OwnedBy` or `Application.ReadWrite.All`

-> When using the `Application.ReadWrite.OwnedBy` application role, you should ensure that the principal being used to run Terraform is included in the `owners` property.

-> It is usually possible to create applications using this resource with just the `Application.ReadWrite.OwnedBy` application role, provided the principal being used to run Terraform is included in the `owners` property. However, this is not officially supported by the API so if you receive a `403` you need to investigate what API call is failing and add additional permissions as necessary. One commonly needed additional permission is `User.Read.All`, in case you specify additional `owners`.
Additionally, you may need the `User.Read.All` application role when including user principals in the `owners` property.

When authenticated with a user principal, this resource requires one of the following directory roles: `Application Administrator` or `Global Administrator`
When authenticated with a user principal, this resource may require one of the following directory roles: `Application Administrator` or `Global Administrator`

## Example Usage

Expand Down Expand Up @@ -199,6 +203,9 @@ The following arguments are supported:
-> **Tags and Features** Azure Active Directory uses special tag values to configure the behavior of applications. These can be specified using either the `tags` property or with the `feature_tags` block. If you need to set any custom tag values not supported by the `feature_tags` block, it's recommended to use the `tags` property. Tag values also propagate to any linked service principals.

* `template_id` - (Optional) Unique ID for a templated application in the Azure AD App Gallery, from which to create the application. Changing this forces a new resource to be created.

-> **Tip for Gallery Applications** This resource can be used to instantiate a gallery application, however it will also attempt to manage the properties of the resulting application. If this is not desired, consider using the [azuread_application_registration](application_registration.html) resource instead.

* `terms_of_service_url` - (Optional) URL of the application's terms of service statement.
* `web` - (Optional) A `web` block as documented below, which configures web related settings for this application.

Expand Down Expand Up @@ -324,7 +331,7 @@ The following arguments are supported:
In addition to all arguments above, the following attributes are exported:

* `app_role_ids` - A mapping of app role values to app role IDs, intended to be useful when referencing app roles in other resources in your configuration.
* `application_id` - The Application ID (also called Client ID).
* `client_id` - The Client ID for the application.
* `disabled_by_microsoft` - Whether Microsoft has disabled the registered application. If the application is disabled, this will be a string indicating the status/reason, e.g. `DisabledDueToViolationOfServicesAgreement`
* `logo_url` - CDN URL to the application's logo, as uploaded with the `logo_image` property.
* `oauth2_permission_scope_ids` - A mapping of OAuth2.0 permission scope values to scope IDs, intended to be useful when referencing permission scopes in other resources in your configuration.
Expand All @@ -336,5 +343,5 @@ In addition to all arguments above, the following attributes are exported:
Applications can be imported using their object ID, e.g.

```shell
terraform import azuread_application.test 00000000-0000-0000-0000-000000000000
terraform import azuread_application.example 00000000-0000-0000-0000-000000000000
```
92 changes: 92 additions & 0 deletions docs/resources/application_api_access.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
---
subcategory: "Applications"
---

# Resource: azuread_application_api_access

Manages the API permissions for an application registration.

This resource is analogous to the `required_resource_access` block in the `azuread_application` resource. When using these resources together, you should use the `ignore_changes` [lifecycle meta-argument](https://developer.hashicorp.com/terraform/language/meta-arguments/lifecycle) (see example below).

## API Permissions

The following API permissions are required in order to use this resource.

When authenticated with a service principal, this resource requires one of the following application roles: `Application.ReadWrite.OwnedBy` or `Application.ReadWrite.All`

-> When using the `Application.ReadWrite.OwnedBy` application role, the principal being used to run Terraform must be an owner of the application.

When authenticated with a user principal, this resource may require one of the following directory roles: `Application Administrator` or `Global Administrator`

## Example Usage

```terraform
data "azuread_application_published_app_ids" "well_known" {}

data "azuread_service_principal" "msgraph" {
client_id = data.azuread_application_published_app_ids.well_known.result["MicrosoftGraph"]
}

resource "azuread_application_registration" "example" {
display_name = "example"
}

resource "azuread_application_api_access" "example_msgraph" {
application_id = azuread_application_registration.example.id
api_client_id = data.azuread_application_published_app_ids.well_known.result["MicrosoftGraph"]

role_ids = [
azuread_service_principal.msgraph.app_role_ids["Group.Read.All"],
azuread_service_principal.msgraph.app_role_ids["User.Read.All"],
]

scope_ids = [
azuread_service_principal.msgraph.oauth2_permission_scope_ids["User.ReadWrite"],
]
}
```

-> **Tip** For managing permissions for an additional API, create another instance of this resource

*Usage with azuread_application resource*

```terraform

resource "azuread_application" "example" {
display_name = "example"

lifecycle {
ignore_changes = [
required_resource_access,
]
}
}

resource "azuread_application_api_access" "example" {
application_id = azuread_application.example.id
# ...
}
```

## Argument Reference

The following arguments are supported:

* `api_client_id` - (Required) The client ID of the API to which access is being granted. Changing this forces a new resource to be created.
* `application_id` - (Required) The resource ID of the application registration. Changing this forces a new resource to be created.
* `role_ids` - (Optional) A set of role IDs to be granted to the application, as published by the API.
* `scope_ids` - (Optional) A set of scope IDs to be granted to the application, as published by the API.

-> At least one of `role_ids` or `scope_ids` must be specified.

## Attributes Reference

No additional attributes are exported.

## Import

Application API Access can be imported using the object ID of the application and the client ID of the API, in the following format.

```shell
terraform import azuread_application_api_access.example /applications/00000000-0000-0000-0000-000000000000/apiAccess/11111111-1111-1111-1111-111111111111
```
Loading
Loading