You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Planning failed. Terraform encountered an error while generating this plan.
╷
│ Error: Retrieving Application with object ID "0efb6050-3049-415e-83e7-4d3f3c4d6f92"
│
│ with azuread_application.sso_app,
│ on ad.tf line 1, in resource "azuread_application" "sso_app":
│ 1: resource "azuread_application" "sso_app" {
│
│ ApplicationsClient.BaseClient.Get(): unexpected status 403 with OData
│ error: Authorization_RequestDenied: Insufficient privileges to complete the
│ operation.
╵
╷
│ Error: Unauthorized
│
│ with kubernetes_namespace.argocd,
│ on main.tf line 1, in resource "kubernetes_namespace" "argocd":
│ 1: resource "kubernetes_namespace" "argocd" {
│
╵
time=2024-06-11T14:30:55Z level=error msg=terraform invocation failed in /builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd/.terragrunt-cache/WtvgRNsKGK4kxhkbvUCP4kWR5Is/YKKYT5K-8aPuzHHttAxD0K0sA20/azure/argocd prefix=[/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd]
time=2024-06-11T14:30:55Z level=error msg=Module /builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd has finished with an error: 1 error occurred:
* [/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd/.terragrunt-cache/WtvgRNsKGK4kxhkbvUCP4kWR5Is/YKKYT5K-8aPuzHHttAxD0K0sA20/azure/argocd] exit status 1
prefix=[/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd]
time=2024-06-11T14:30:55Z level=info msg=╷
│ Error: Retrieving Application with object ID "0efb6050-3049-415e-83e7-4d3f3c4d6f92"
│
│ with azuread_application.sso_app,
│ on ad.tf line 1, in resource "azuread_application" "sso_app":
│ 1: resource "azuread_application" "sso_app" {
│
│ ApplicationsClient.BaseClient.Get(): unexpected status 403 with OData
│ error: Authorization_RequestDenied: Insufficient privileges to complete the
│ operation.
╵
╷
│ Error: Unauthorized
│
│ with kubernetes_namespace.argocd,
│ on main.tf line 1, in resource "kubernetes_namespace" "argocd":
│ 1: resource "kubernetes_namespace" "argocd" {
│
╵
time=2024-06-11T14:30:55Z level=error msg=terraform invocation failed in /builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd/.terragrunt-cache/WtvgRNsKGK4kxhkbvUCP4kWR5Is/YKKYT5K-8aPuzHHttAxD0K0sA20/azure/argocd prefix=[/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd]
time=2024-06-11T14:30:55Z level=error msg=1 error occurred:
* [/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd/.terragrunt-cache/WtvgRNsKGK4kxhkbvUCP4kWR5Is/YKKYT5K-8aPuzHHttAxD0K0sA20/azure/argocd] exit status 1
Panic Output
Expected Behavior
terraform plan should have passed
Actual Behavior
terraform plan fails complaining insufficient privileges to complete the operation. The service principal used to run the terraform is member of Application Administrator role under EntraID and have also been given additional graphAPI permissions for Directory
Steps to Reproduce
terraform plan
Important Factoids
References
#0000
The text was updated successfully, but these errors were encountered:
Specifically which Graph API permissions has been added to the service principal used to run Terraform?
Is this kubernetes_namespace resource related to this? Don't see that in the pasted configuration.
manicminer
changed the title
Authorization_RequestDenied: Insufficient privileges to complete the operation
azuread_application: Authorization_RequestDenied: Insufficient privileges to complete the operation
Jun 17, 2024
Community Note
Terraform (and AzureAD Provider) Version
terraform_1.8.1_linux_amd64
Affected Resource(s)
azuread_application
Terraform Configuration Files
Debug Output
Planning failed. Terraform encountered an error while generating this plan.
╷
│ Error: Retrieving Application with object ID "0efb6050-3049-415e-83e7-4d3f3c4d6f92"
│
│ with azuread_application.sso_app,
│ on ad.tf line 1, in resource "azuread_application" "sso_app":
│ 1: resource "azuread_application" "sso_app" {
│
│ ApplicationsClient.BaseClient.Get(): unexpected status 403 with OData
│ error: Authorization_RequestDenied: Insufficient privileges to complete the
│ operation.
╵
╷
│ Error: Unauthorized
│
│ with kubernetes_namespace.argocd,
│ on main.tf line 1, in resource "kubernetes_namespace" "argocd":
│ 1: resource "kubernetes_namespace" "argocd" {
│
╵
time=2024-06-11T14:30:55Z level=error msg=terraform invocation failed in /builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd/.terragrunt-cache/WtvgRNsKGK4kxhkbvUCP4kWR5Is/YKKYT5K-8aPuzHHttAxD0K0sA20/azure/argocd prefix=[/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd]
time=2024-06-11T14:30:55Z level=error msg=Module /builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd has finished with an error: 1 error occurred:
* [/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd/.terragrunt-cache/WtvgRNsKGK4kxhkbvUCP4kWR5Is/YKKYT5K-8aPuzHHttAxD0K0sA20/azure/argocd] exit status 1
prefix=[/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd]
time=2024-06-11T14:30:55Z level=info msg=╷
│ Error: Retrieving Application with object ID "0efb6050-3049-415e-83e7-4d3f3c4d6f92"
│
│ with azuread_application.sso_app,
│ on ad.tf line 1, in resource "azuread_application" "sso_app":
│ 1: resource "azuread_application" "sso_app" {
│
│ ApplicationsClient.BaseClient.Get(): unexpected status 403 with OData
│ error: Authorization_RequestDenied: Insufficient privileges to complete the
│ operation.
╵
╷
│ Error: Unauthorized
│
│ with kubernetes_namespace.argocd,
│ on main.tf line 1, in resource "kubernetes_namespace" "argocd":
│ 1: resource "kubernetes_namespace" "argocd" {
│
╵
time=2024-06-11T14:30:55Z level=error msg=terraform invocation failed in /builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd/.terragrunt-cache/WtvgRNsKGK4kxhkbvUCP4kWR5Is/YKKYT5K-8aPuzHHttAxD0K0sA20/azure/argocd prefix=[/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd]
time=2024-06-11T14:30:55Z level=error msg=1 error occurred:
* [/builds/infra/environment_definitions/nonprod/projects/platform/poc/uksouth/cluster/argocd/.terragrunt-cache/WtvgRNsKGK4kxhkbvUCP4kWR5Is/YKKYT5K-8aPuzHHttAxD0K0sA20/azure/argocd] exit status 1
Panic Output
Expected Behavior
terraform plan should have passed
Actual Behavior
terraform plan fails complaining insufficient privileges to complete the operation. The service principal used to run the terraform is member of Application Administrator role under EntraID and have also been given additional graphAPI permissions for Directory
Steps to Reproduce
terraform plan
Important Factoids
References
The text was updated successfully, but these errors were encountered: