ARM template Key Vault - Invalid value for "accessPolicies" - azure-resource-manager

I need to configure key vault permissions for a FunctionApp. I am getting the error "An invalid value was provided for 'accessPolicies'.
Here is my variable declartion,
"variables": {
"identityResourceId": "[concat(resourceId('Microsoft.Web/sites/',variables('functionAppName')),'/providers/Microsoft.ManagedIdentity/Identities/default')]"
Here is my "output" section,
"outputs": {
"AppObjectId": {
"type": "string",
"value": "[reference(variables('identityResourceId'), '2015-08-31-PREVIEW').principalId]"
I am not receiving the correct "ObjectID" value into the output variable "AppObjectId". Any help will be appreciated.


HAPI FHIR try to use patch

I've this resource of type Paramaters as follow:
"resourceType": "Parameters",
"parameter": [
"name": "operation",
"part": [
"name": "type",
"valueCode": "add"
"name": "path",
"valueString": "Organization"
"name": "name",
"valueString": "active"
"name": "value",
"valueString": "true"
Because I want to add active value on my Organization.
So I write, in according with HAPI FHIR documentation - 4.2.7 paragraph, this code to execute a patch:
But I have this error: HTTP 400 :
Cannot deserialize instance of
out of FIELD_NAME token at [Source: UNKNOWN; line: -1, column: -1]
I've noticed I must put in the same array all informations about patch (in the tag part), but I don't know I can resolve it.
Tha HAPI FHIR version is 4.2.0

How should a "write" request be structured for Firestore REST API (v1beta1)?

Based on the Google Discovery document, and RPC reference, it appears that the :write resource should be available for Firestore database interactions, but performing such a request to my (POST[my project]/databases/(default)/documents:write) results in:
"error": {
"code": 400,
"message": "Invalid value (Object), ",
"details": [
"#type": "",
"fieldViolations": [
"description": "Invalid value (Object), "
Is this possible? A related SO answer alludes to this being available as a means of field transforms, the same reason I require this, but I cannot construct valid a JSON body to succeed in the request. Currently, variations on the following don't work as expected when trying a minimum successful response:
"writes": [
"update": {
"name": "projects/{projectId}/databases/[my project]/documents/exampleId",
"fields": {
"example": {
"integerValue": 100
"timestamp": {
"nullValue": null
"transform": {
"document": "projects/[my project]]/databases/(default)/documents/examples/exampleId",
"fieldTransforms": [
"fieldPath": "timestamp",
"setToServerValue": "REQUEST_TIME"
First of all, note that you should use the v1 version of the REST API, not the betas.
To create a document, you would use the createDocument method, while to update a document you would use the patch one.
For the document creation you should therefore make a POST HTTP Request to the following URL<your-project-id>/databases/(default)/documents/<the-desired-collection>
with the following Request body:
fields: {
example: {
integerValue: 100
You need to use documents:commit instead of documents:write
also the name field should be in this format:
"name": "projects/projectID/databases/(default)/documents/collectionName/DocumentId"
See this post.

JAGQL - Why do I need an id for a post call?

I'm using JAGQL to build a JSON API compatible express server. My database behind it is MongoDB (jsonapi-store-mongodb). I posted my question here as well:
According to the JAGQL documentation,,
I am told that
By default, the server autogenerates a UUID for resources which are created without specifying an ID. To disable this behavior (for example, if the database generates an ID by auto-incrementing), set generateId to false. If the resource's ID is not a UUID, it is also necessary to specify an id attribute with the correct type. See /examples/resorces/autoincrement.js for an example of such a resource.
But when I send a POST request to one of my resources, I get this:
"jsonapi": {
"version": "1.0"
"meta": {},
"links": {
"self": "/myresource"
"errors": [
"status": "403",
"code": "EFORBIDDEN",
"title": "Param validation failed",
"detail": [
"message": "\"id\" is required",
"path": [
"type": "any.required",
"context": {
"key": "id",
"label": "id"
What am I missing?
See here for more details:
In your resource definition, you want to add primaryKey: 'uuid':
resource: 'things',
primaryKey: 'uuid',
attributes: {

Get CosmosDb Primary Connection String in ARM template

I have an ARM template which sources the primaryMasterKey of a cosmosDb as follows:
"properties": {
"enabled": true,
"siteConfig": {
"appSettings": [
"name": "MongoDb:CnnDetails",
"value": "[listKeys(resourceId('Microsoft.DocumentDB/databaseAccounts', variables('cosmosdb_full')), '2015-04-08').primaryMasterKey]"
How to I modify it to get the actual connection string instead?
I've tried couple of things:
changed the word primaryMasterKey to primaryConnectionString. This gives an error saying:
'The language expression property 'primaryConnectionString' doesn't exist, available properties are 'primaryMasterKey, secondaryMasterKey, primaryReadonlyMasterKey, secondaryReadonlyMasterKey'
changed the work listKeys to listConnectionStrings. This is red underlined in my visual studio, but seems to work when put through azure devops
'The language expression property 'primaryConnectionString' doesn't exist, available properties are 'connectionStrings'
I went to to try it out. ListKeys returns a structure like this:
"primaryMasterKey": "[REDACTED]",
"secondaryMasterKey": "[REDACTED]",
"primaryReadonlyMasterKey": "[REDACTED]",
"secondaryReadonlyMasterKey": "[REDACTED]"
so I get why the .primaryMasterKey worked. But ListConnectionStrings returns:
"connectionStrings": [
"connectionString": "mongodb://[REDACTED]:10255/?ssl=true&replicaSet=globaldb",
"description": "Primary MongoDB Connection String"
"connectionString": "mongodb://[REDACTED]:10255/?ssl=true&replicaSet=globaldb",
"description": "Secondary MongoDB Connection String"
"connectionString": "mongodb://[REDACTED]:10255/?ssl=true&replicaSet=globaldb",
"description": "Primary Read-Only MongoDB Connection String"
"connectionString": "mongodb://[REDACTED]:10255/?ssl=true&replicaSet=globaldb",
"description": "Secondary Read-Only MongoDB Connection String"
Not sure how to "index into it"?
Any clues gratefully received.
For anyone else finding this question and wanting a fully complete ARM Template snippet, this is what I have used and is working:
"connectionStrings": [
"name": "CosmosConnection",
"connectionString": "[listConnectionStrings(resourceId('Microsoft.DocumentDB/databaseAccounts', parameters('cosmosDbAccountName')), '2019-12-12').connectionStrings[0].connectionString]",
"type": 3
like you normally would in almost any language:
index starts at 0.
you have a more "native" way of doing this:
but only available functions are first and last
The answer here by oatsoda is correct but it will only work if you are within the same resource group as the Cosmos DB you are getting the connection string for. If you have the scenario where you Cosmos DB is in a different resource group to the resource you are generating an ARM template for the following snippet is what I have used to generate the connection string for an App Service and is working.
"Cosmos": {
"value": "[listConnectionStrings(resourceId(parameters('cosmosResourceGroupName'),'Microsoft.DocumentDB/databaseAccounts', parameters('cosmosDbName')), '2019-12-12').connectionStrings[0].connectionString]",
"type": "Custom"
In the Cosmos linked ARM template named linkedTemplate_cosmos_db-gdp-event-ammi-dev-ne-001 I used the following code.
"outputs": {
"ConnectionString": {
"value": "[listConnectionStrings(resourceId('Microsoft.DocumentDB/databaseAccounts', parameters('accountName')), '2019-12-12').connectionStrings[0].connectionString]",
"name": "CosmosConnection",
"type": "string"
and then in the ARM template (linkedTemplate_Main) that uses the output parameter, the following, e.g a function app configuration setting
"value": "[reference('linkedTemplate_cosmos_db-gdp-event-ammi-dev-ne-001').outputs.ConnectionString.value]"

Refs to # in a definition don't parse schema

I have a schema that has a 'manager' property which is a user object:
"id": "",
"manager": {
"anyOf": [{
"$ref": "#/definitions/user"
"title": "Manager"
The #/definitions/user schema is:
"definitions": {
"user": {
"$ref": "#"
This results in a "Error when resolving schema reference '#'. Path 'definitions.user'" error.
Addressing the user with "$ref": "#" from the manager property isn't an option as we are using the definition to help build the UI and need a common definition.
Edit: added the "id" property which was a critical omission in this.
This works:
"id": "",
Edit: Added fixed "id" field with http:// qualification added.
