Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1946216

Summary: Service Principal on Azure
Product: OpenShift Container Platform Reporter: Nelson Lombo Paez <npaez>
Component: DocumentationAssignee: Steven Smith <stevsmit>
Status: CLOSED CURRENTRELEASE QA Contact: Gaoyun Pei <gpei>
Severity: medium Docs Contact: Latha S <lmurthy>
Priority: medium    
Version: 4.6CC: aos-bugs, aramesha, jokerman, lmurthy, xtian
Target Milestone: ---   
Target Release: 4.7.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-18 13:12:01 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Nelson Lombo Paez 2021-04-05 12:24:30 UTC
Document URL: https://docs.openshift.com/container-platform/4.7/installing/installing_azure/installing-azure-customizations.html

Section Number and Name: Sample customized install-config.yaml file for Azure

Describe the issue: 

Sates explicitly that permissions on service principal should be granted at the subscription level, granting them at resource group level is not enough

Suggestions for improvement: Mention all of the permissions that are required to install the cluster

Additional information: 

For example the servicePrincipal has permissions at the RG level and it probably should have these permissions at a higher level. 
Is there any way to work within one provided RG without needed multiple ones? That could be good added to the documentation

Comment 2 Steven Smith 2021-10-08 19:54:51 UTC
PR: https://github.com/openshift/openshift-docs/pull/37275

@

Comment 3 Steven Smith 2021-10-08 19:57:25 UTC
@lmurthy @xtian I need a QE assigned to this bug :)