Skip to content

Azure PIM: pre-flight cap activation duration at the role's PIM policy maximum #3238

Description

@aknysh

What

The azure/pim-role identity (PRD: docs/prd/azure-pim-role-identity.md) converts the configured Go-style duration to ISO-8601 and sends it on the PIM SelfActivate request. It does not pre-flight the role's PIM activation-policy maximum. If the configured window exceeds that maximum, Azure Resource Manager rejects the request server-side.

Today that rejection is handled gracefully: the create-failure path surfaces ARM's own message plus an actionable Atmos hint to lower duration (see submitActivation in pkg/auth/identities/azure/pim_role.go). This issue tracks closing the remaining gap: cap the duration before filing the request so a too-long window succeeds (clamped) instead of failing.

Proposed implementation

  • Query roleManagementPolicyAssignments for the scope, find the assignment for the target role definition, and read the activation RoleManagementPolicyExpirationRule's maximumDuration (ISO-8601).
  • Clamp the effective duration to min(configured, policyMax) in the azure/pim-role identity before building the ActivationRequest.
  • Add a PolicyMaxDuration-style method to the PIMClient interface (and the armPIMClient ARM implementation), mocked in unit tests.
  • Emit a debug/warn log when the configured duration is clamped.

Why it's deferred

  • The common case (duration within policy) already works, and over-long durations already fail with a clear, actionable error.
  • Pre-flight capping adds an extra ARM round-trip to every activation plus a policy-rule parser, so it was split out to keep the initial PR focused.

References

  • PRD: docs/prd/azure-pim-role-identity.md (section 5, Deferred)
  • Identity: pkg/auth/identities/azure/pim_role.go
  • PIM client: pkg/auth/identities/azure/pim_client.go
  • Microsoft docs: Role Management Policy Assignments (Authorization RBAC REST)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions