{"record":{"id":"429688d0c8fc830e","repo":"kubernetes/kops","slug":"unsupported-resource-type-q","errorCode":null,"errorMessage":"unsupported resource type %q","messagePattern":"unsupported resource type %q","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"upup/pkg/fi/cloudup/azure/verifier.go","lineNumber":141,"sourceCode":"\n\t// Reject resource IDs outside the verifier's own subscription / resource group. The Azure API lookup below\n\t// is already scoped to kops-controller's subscription and resource group, so any claim that names a different\n\t// location cannot describe a cluster VM. Failing here avoids a wasted Azure API call and makes the scope\n\t// explicit instead of implicit.\n\tif !strings.EqualFold(res.SubscriptionID, a.client.subscriptionID) {\n\t\treturn nil, fmt.Errorf(\"resource ID subscription %q does not match verifier subscription %q\", res.SubscriptionID, a.client.subscriptionID)\n\t}\n\tif !strings.EqualFold(res.ResourceGroupName, a.client.resourceGroup) {\n\t\treturn nil, fmt.Errorf(\"resource ID resource group %q does not match verifier resource group %q\", res.ResourceGroupName, a.client.resourceGroup)\n\t}\n\tswitch resourceType {\n\tcase vmResourceType:\n\tcase vmssVMResourceType:\n\t\tif !strings.HasSuffix(res.Parent.Name, \".\"+a.clusterName) {\n\t\t\treturn nil, fmt.Errorf(\"resource ID VMSS name %q does not match cluster name %q\", res.Parent.Name, a.clusterName)\n\t\t}\n\tdefault:\n\t\treturn nil, fmt.Errorf(\"unsupported resource type %q\", resourceType)\n\t}\n\n\t// Verify the PKCS7 attested document: signature, certificate chain, nonce, and expiration.\n\tdata, err := a.attestation.verifyAttestedDocument(signature, body)\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\tklog.V(2).Infof(\"Azure verifier for VM %q verified attested document\", vmLogID)\n\tif !strings.EqualFold(data.SubscriptionId, a.client.subscriptionID) {\n\t\treturn nil, fmt.Errorf(\"attested subscriptionId %q does not match verifier subscription %q\", data.SubscriptionId, a.client.subscriptionID)\n\t}\n\n\t// Look up the VM or VMSS VM via the Azure API using the resource ID, cross-verify the attested\n\t// vmId, and extract node identity.\n\tvar nodeName, igName string\n\tvar addrs, challengeEndpoints []string\n\n\tswitch resourceType {","sourceCodeStart":123,"sourceCodeEnd":159,"githubUrl":"https://github.com/kubernetes/kops/blob/4c8573c808a73d578c5eadc86d410646ea0b0d73/upup/pkg/fi/cloudup/azure/verifier.go#L123-L159","documentation":"The resource ID in the token names a resource type other than the two supported kinds (a standalone virtualMachine or a virtualMachineScaleSet VM). The verifier can only attest these types; any other ARM resource type is rejected by the switch default before attestation checking.","triggerScenarios":"Thrown at upup/pkg/fi/cloudup/azure/verifier.go:141 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Ensure the token was minted by a node running on an Azure VM or VMSS VM instance","Check for a malformed or hand-crafted resource ID in the token","Extend the verifier's resource-type switch only if a new node type is officially supported"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"4c8573c808a73d578c5eadc86d410646ea0b0d73","analyzedAt":"2026-09-05T04:13:19.212Z","contentChangedAt":"2026-09-05T04:13:19.212Z","schemaVersion":2},"datasetVersion":"2026-09-12T07:17:12.445Z"}