Skip to content

Lab-grown Azure.Real identity. Real RBAC. On your machine.

A local Azure emulator. Your application, the Azure CLI, the SDKs and Terraform talk to Armite exactly as they talk to Azure, and a principal without the right role gets the same 403 it would get in production.

The Armite crystalThe Armite crystal

"But I'm Owner?!" ​

text
$ az keyvault secret set --vault-name kv-demo -n db-pass --value hunter2
(Forbidden) Caller is not authorized to perform action on resource.
Caller: appid=33333333-...;oid=44444444-...
Action: 'Microsoft.KeyVault/vaults/secrets/setSecret/action'
Resource: '/subscriptions/.../vaults/kv-demo/secrets/db-pass'
DecisionReason: 'DeniedWithNoValidRBAC'
Inner error: {"code": "ForbiddenByRbac"}

That caller is Owner of the subscription. Owner carries every management-plane action and not one data-plane action, so on an RBAC-mode vault it cannot read or write a secret until a data role such as Key Vault Secrets Officer is assigned. It is one of Azure's most common surprises; with Armite it happens on your laptop and in CI instead of in production.

Run this demo yourself →

Released under the Apache License 2.0. Azure, Entra and Key Vault are Microsoft trademarks; Armite is not affiliated with or endorsed by Microsoft.