v0.6.51: Runs that respect Assignment required
Managed runs keep working when you turn on Assignment required for the Maester Cloud app, and every run's console now covers the upload and processing steps.
What’s new
- Restrict sign-in without breaking runs. You can turn on Assignment required for the Maester Cloud enterprise application to limit who can sign in, and managed runs keep working. Each run checks in by signing in to that app with your deployment’s runner managed identity. Before this release nothing assigned that identity to the app, so once assignment was required, every run stopped at Starting runner with
AADSTS501051. Setup now gives the runner identity Default Access on the app, and nothing else.
Fixes
- A managed run’s console now shows the runner uploading its report and ends with how processing went: the result counts when it succeeds, or the reason when it fails. Before, the console stopped just before the upload.
- If a run is refused with
AADSTS501051, its console now says how to fix it and includes a PowerShell script already filled in with your deployment’s IDs. - Setup keeps your sign-ins when the browser comes back from a Microsoft sign-in. Some browsers, including Chrome in Incognito, could restore an earlier copy of the page’s storage on the way back, so setup reported “The sign-in response state was invalid” and asked you to sign in again. Two sign-ins started close together no longer overwrite each other either.
- The Email step sets the sender mailbox’s profile picture without an extra sign-in whenever your Microsoft sign-in allows it, and offers Sign in to Microsoft Graph only when consent is needed.
- Sign-in hardening: a deployment that runs in Development mode with Entra sign-in configured no longer accepts the local development sign-in header, and the API accepts only RS256-signed tokens.
How to update
- Open setup.maester.cloud and sign in with the account you used for setup.
- Choose your instance and select Update. The update applies in place, and your stored results and history are untouched.
- On the Portal sign-in step, check the Runner identity card. If it doesn’t say the runner identity is assigned, choose Assign the runner identity. This needs an account that can grant app role assignments, such as a Cloud Application Administrator. The card also offers a script you can hand to an administrator instead. Do this before you turn on Assignment required; if it’s already on, managed runs start working again once the identity is assigned.
If you run setup from PowerShell, update the module first with Update-Module MaesterCloud -AllowPrerelease, then run Start-MaesterCloudSetup. It opens the same setup steps on your machine, so follow steps 2 and 3 there.