Skip to content

Add Key Vault RBAC private access fixtures#1519

Open
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/azure-kv-rbac-fixtures-1511
Open

Add Key Vault RBAC private access fixtures#1519
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/azure-kv-rbac-fixtures-1511

Conversation

@jddark62
Copy link
Copy Markdown

@jddark62 jddark62 commented Jun 6, 2026

Summary

Strengthens azure-review for Key Vault RBAC transition and private endpoint enforcement.

This adds:

  • Key Vault RBAC evidence requirements for data-plane role assignments, management-plane grant authority, group expansion, live role export, migration drift, owner, expiry, and review evidence.
  • Private access enforcement checks for public network access, firewall default action, AzureServices bypass, private endpoint subresource, private DNS, client resolution, diagnostics, and deployment-agent exceptions.
  • Output fields for evidence confidence, Not Evaluable reasons, and a Key Vault RBAC/private access evidence table.
  • Seven YAML calibration fixtures covering controlled RBAC/private access, broad data-plane admin roles, migration drift, public paths left open, missing private DNS, unsupported bypass exceptions, and hosted CI/CD access exceptions.

Validation

  • git diff --check
  • Skill frontmatter YAML parse
  • Fixture YAML parse: 7 YAML blocks
  • Markdown fence balance check
  • Public-file privacy scan
  • Microsoft Learn references checked for Key Vault RBAC, RBAC migration, and network security pages

/claim #1511

Payment details can be coordinated privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant