What
The azure/pim-role identity (PRD: docs/prd/azure-pim-role-identity.md) converts the configured Go-style duration to ISO-8601 and sends it on the PIM SelfActivate request. It does not pre-flight the role's PIM activation-policy maximum. If the configured window exceeds that maximum, Azure Resource Manager rejects the request server-side.
Today that rejection is handled gracefully: the create-failure path surfaces ARM's own message plus an actionable Atmos hint to lower duration (see submitActivation in pkg/auth/identities/azure/pim_role.go). This issue tracks closing the remaining gap: cap the duration before filing the request so a too-long window succeeds (clamped) instead of failing.
Proposed implementation
- Query
roleManagementPolicyAssignments for the scope, find the assignment for the target role definition, and read the activation RoleManagementPolicyExpirationRule's maximumDuration (ISO-8601).
- Clamp the effective duration to
min(configured, policyMax) in the azure/pim-role identity before building the ActivationRequest.
- Add a
PolicyMaxDuration-style method to the PIMClient interface (and the armPIMClient ARM implementation), mocked in unit tests.
- Emit a debug/warn log when the configured duration is clamped.
Why it's deferred
- The common case (duration within policy) already works, and over-long durations already fail with a clear, actionable error.
- Pre-flight capping adds an extra ARM round-trip to every activation plus a policy-rule parser, so it was split out to keep the initial PR focused.
References
- PRD:
docs/prd/azure-pim-role-identity.md (section 5, Deferred)
- Identity:
pkg/auth/identities/azure/pim_role.go
- PIM client:
pkg/auth/identities/azure/pim_client.go
- Microsoft docs: Role Management Policy Assignments (Authorization RBAC REST)
What
The
azure/pim-roleidentity (PRD:docs/prd/azure-pim-role-identity.md) converts the configured Go-styledurationto ISO-8601 and sends it on the PIMSelfActivaterequest. It does not pre-flight the role's PIM activation-policy maximum. If the configured window exceeds that maximum, Azure Resource Manager rejects the request server-side.Today that rejection is handled gracefully: the create-failure path surfaces ARM's own message plus an actionable Atmos hint to lower
duration(seesubmitActivationinpkg/auth/identities/azure/pim_role.go). This issue tracks closing the remaining gap: cap the duration before filing the request so a too-long window succeeds (clamped) instead of failing.Proposed implementation
roleManagementPolicyAssignmentsfor the scope, find the assignment for the target role definition, and read the activationRoleManagementPolicyExpirationRule'smaximumDuration(ISO-8601).min(configured, policyMax)in theazure/pim-roleidentity before building theActivationRequest.PolicyMaxDuration-style method to thePIMClientinterface (and thearmPIMClientARM implementation), mocked in unit tests.Why it's deferred
References
docs/prd/azure-pim-role-identity.md(section 5, Deferred)pkg/auth/identities/azure/pim_role.gopkg/auth/identities/azure/pim_client.go