Skip to content

fix(check): report cluster access-denied per resource instead of false negatives - #902

Merged
Ketki Naik (ketkimnaik) merged 10 commits into
Azure:devfrom
ketkimnaik:fix-ops-nega-false-issue
Jul 23, 2026
Merged

fix(check): report cluster access-denied per resource instead of false negatives#902
Ketki Naik (ketkimnaik) merged 10 commits into
Azure:devfrom
ketkimnaik:fix-ops-nega-false-issue

Conversation

@ketkimnaik

@ketkimnaik Ketki Naik (ketkimnaik) commented Jul 16, 2026

Copy link
Copy Markdown
Contributor
  • az iot ops check now detects Kubernetes 401/403 responses when reading Azure IoT Operations resources and reports a precise per-resource "Access denied (HTTP 403)" (with a permissions footer in the summary), instead of misleading "Unable to fetch … in any namespace" false negatives.
  • Handling is per resource, so partial-access principals still see valid results for resources they can read, while only the forbidden ones are flagged — no full-command abort.

Before change overall output:

image

It does not show clear message and fails the check.

After change applied:

  1. For overall command:
image
  1. For per service:
image

It shows detailed error.


This project has adopted the Microsoft Open Source Code of Conduct. For more information see the Code of Conduct FAQ or contact opencode@microsoft.com with any additional questions or comments.

Thank you for contributing to Azure IoT Operations tooling!

This checklist is used to make sure that common guidelines for a pull request are followed.

General Guidelines

Intent for Production

  • It is expected that pull requests made to default or core branches such as dev or main are of production grade. Corollary to this, any merged contributions to these branches may be deployed in a public release at any given time. By checking this box, you agree and commit to the expected production quality of code.

Basic expectations

  • If introducing new functionality or modified behavior, are they backed by unit and/or integration tests?
  • In the same context as above are command names and their parameter definitions accurate? Do help docs have sufficient content?
  • Have all the relevant unit and integration tests pass? i.e. pytest <project root> -vv. Please provide evidence in the form of a screenshot showing a succesful run of tests locally OR a link to a test pipeline that has been run against the change-set.
  • Have linter checks passed using the .pylintrc and .flake8 rules? Look at the CI scripts for example usage.
  • Have extraneous print or debug statements, commented out code-blocks or code-statements (if any) been removed from the surface area of changes?
  • Have you made an entry in HISTORY.rst which concisely explains your user-facing feature or change?

Azure IoT Operations CLI maintainers reserve the right to enforce any of the outlined expectations.

A PR is considered ready for review when all basic expectations have been met (or do not apply).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Comment thread azext_edge/edge/providers/check/base/resource.py Outdated
Comment thread azext_edge/edge/providers/check/base/deployment.py
Comment thread azext_edge/edge/providers/check/base/deployment.py
Comment thread azext_edge/edge/providers/base.py Outdated
Comment thread azext_edge/edge/providers/check/base/deployment.py

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.

Comment thread azext_edge/edge/providers/base.py
Comment thread azext_edge/edge/providers/k8s/config_map.py
Comment thread azext_edge/edge/providers/check/mq.py
Comment thread azext_edge/edge/providers/check/mq.py
@ketkimnaik
Ketki Naik (ketkimnaik) merged commit 1d3091c into Azure:dev Jul 23, 2026
51 of 59 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants