Skip to content

Move chef_license_key to protectedSettings for Azure Chef Extension - #4761

Merged
IanMadd merged 3 commits into
mainfrom
docs/azure-chef-extension-protected-license-key
Sep 29, 2026
Merged

IanMadd merged 3 commits into
mainfrom
docs/azure-chef-extension-protected-license-key

Conversation

@tpowell-progress

Copy link
Copy Markdown
Contributor

Description

Follows up on #4743, which documented chef_license_key as a public extension setting for the Azure Chef Extension.

This documents the security fix in chef-partners/azure-chef-extension#413: chef_license_key should be set under protectedSettings, not public settings. Public settings/ARM deployment parameters are readable via ARM deployment history and by anyone with Reader access to the VM extension resource, which exposes the Chef commercial license key well beyond the node itself.

  • Marks the public-settings chef_license_key option as deprecated (still supported for backward compatibility; the extension logs a deprecation warning).
  • Adds chef_license_key under the Protected settings section as the recommended location.

Updated in both client 18 and client 19 docs.

Related:

Follows up on #4743 (chef_license_key public setting). Documents the fix
in chef-partners/azure-chef-extension#413: chef_license_key should be
set under protectedSettings, not public settings, since public
settings/ARM parameters are readable via ARM deployment history and by
anyone with Reader access to the VM extension resource — that exposes
the Chef commercial license key well beyond the node itself. Public
settings placement is still supported for backward compatibility (the
extension logs a deprecation warning) but is being phased out.

Signed-off-by: Thomas Powell <todd.powell@progress.com>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Todd Powell <todd.powell@progress.com>
@tpowell-progress
tpowell-progress requested a review from a team as a code owner September 28, 2026 17:19
@netlify

netlify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for chef-web-docs ready!

Name Link
🔨 Latest commit 80b9420
🔍 Latest deploy log https://app.netlify.com/projects/chef-web-docs/deploys/6abbd5c04fce2f000783bcce
😎 Deploy Preview https://deploy-preview-4761--chef-web-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@tpowell-progress tpowell-progress added the ai-assisted Work completed with AI assistance following Progress AI policies label Sep 28, 2026
Thomas Powell and others added 2 commits September 29, 2026 07:59
Updates the JSON deployment examples in the client 18/19 azure_chef_cli
docs from the stale 1210.12 reference to the current release,
1210.15.11.1.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Thomas Powell <todd.powell@progress.com>
Signed-off-by: Ian Maddaus <ian.maddaus@progress.com>
@IanMadd
IanMadd merged commit e0c87d0 into main Sep 29, 2026
13 checks passed
@IanMadd
IanMadd deleted the docs/azure-chef-extension-protected-license-key branch September 29, 2026 15:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-assisted Work completed with AI assistance following Progress AI policies Component: Chef Infra Client

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants