HTTP trigger auth bridges
Use this reference when the calling system cannot present the Azure token that Azure SRE Agent expects directly.
Microsoft Learn currently points to three bridge patterns:
- Azure Functions
- Logic Apps
- Azure API Management
Choose a bridge
| Bridge | Best for | Why choose it |
|---|---|---|
| Azure Functions | CI/CD handlers, custom logic, payload shaping | Most flexible code-first bridge with managed identity support |
| Logic Apps | Low-code webhook relay | Fastest path when you want workflow-level orchestration |
| Azure API Management | Central ingress and policy | Strongest fit for shared ingress governance, throttling, and transformation |
Safety defaults
- Keep the downstream HTTP trigger disabled until bridge auth, payload validation, and replay controls are tested.
- Treat the final SRE Agent token audience as
[VERIFY]because the official docs still conflict. - Require correlation and replay-control headers.
- Keep downstream SRE Agent workflows in
Reviewuntil the bridge proves stable and bounded. - Do not forward secrets or raw customer data in the payload body.
Current docs conflict
[VERIFY]
Claim = supported token audience for Azure SRE Agent HTTP trigger invocation
WhereToCheck = https://learn.microsoft.com/en-us/azure/sre-agent/http-triggers
Conflict = one section shows Azure Resource Manager bearer-token guidance, while troubleshooting says the audience must match the SRE Agent app ID instead of https://management.azure.com
Action = verify the current supported audience before shipping the bridge to productionWhat this bundle provides
bundles/http-trigger-auth-bridges/templates/azure-functions-managed-identity-relay.yamlbundles/http-trigger-auth-bridges/templates/logic-app-managed-identity-relay.yamlbundles/http-trigger-auth-bridges/templates/apim-front-door-relay.yamlbundles/http-trigger-auth-bridges/checklists/http-trigger-auth-bridge.md
These are design templates, not import-ready Azure resources. Replace placeholders, validate current platform behavior, and test in non-production first.
Validate before cutover
- bearer-token acquisition path works end to end
- trigger stays disabled until auth is proven
404on disabled triggers is expected during test stages250-turn cap remains acceptable for the downstream workflow- replay and idempotency handling are documented
- rollback path exists for the bridge and the downstream trigger
Sources
Primary source: references/source-map.md → Microsoft Learn http-triggers