Skip to content

Commit 2096907

Browse files
authored
Add Read Action to Role Assignment Condition (#1111)
Signed-off-by: Ian Stanton <ian@tembo.io>
1 parent e8ed810 commit 2096907

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

conductor/src/azure/uami_builder.rs

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -176,12 +176,12 @@ pub async fn create_role_assignment(
176176
!(ActionMatches{{'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write'}})
177177
AND
178178
!(ActionMatches{{'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/add/action'}})
179+
AND
180+
!(ActionMatches{{'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read'}})
179181
)
180182
OR
181183
(
182184
@Resource[Microsoft.Storage/storageAccounts/blobServices/containers:name] StringEquals '{azure_backup_container}'
183-
AND
184-
@Resource[Microsoft.Storage/storageAccounts/blobServices/containers/blobs:path] StringLike '{namespace}/*'
185185
)
186186
)
187187
"

0 commit comments

Comments
 (0)