Skip to content

Commit e6086a1

Browse files
Update main.tf
1 parent 2103eea commit e6086a1

File tree

1 file changed

+9
-12
lines changed

1 file changed

+9
-12
lines changed

main.tf

Lines changed: 9 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -263,18 +263,6 @@ resource "azurerm_key_vault" "kv1" {
263263
storage_permissions = ["Get"]
264264
}
265265

266-
access_policy {
267-
# Access policy for ServiceBus
268-
tenant_id = data.azurerm_client_config.current.tenant_id
269-
object_id = data.azurerm_servicebus_namespace.cs_servicebus_ns[0].principal_id
270-
key_permissions = ["Get", "Create", "List", "Delete", "GetRotationPolicy", "SetRotationPolicy"]
271-
272-
secret_permissions = [
273-
"Get", "Backup", "Delete", "List", "Purge", "Recover", "Restore", "Set",
274-
]
275-
storage_permissions = ["Get"]
276-
}
277-
278266
tags = {
279267
Owner = var.owner_tag
280268
Environment = var.environment_tag
@@ -312,6 +300,15 @@ resource "azurerm_key_vault_access_policy" "cosmosdb" {
312300
key_permissions = ["Get", "WrapKey", "UnwrapKey"]
313301
}
314302

303+
304+
resource "azurerm_key_vault_access_policy" "servicebus" {
305+
key_vault_id = azurerm_key_vault.kv1.id
306+
tenant_id = data.azurerm_client_config.current.tenant_id
307+
object_id = azurerm_servicebus_namespace.cs_servicebus_ns.identity.principal_id
308+
309+
key_permissions = ["Get", "WrapKey", "UnwrapKey"]
310+
}
311+
315312
/*******************************************************************************
316313
CREATE KEY VAULT SECRETS
317314
*******************************************************************************/

0 commit comments

Comments
 (0)