All skills
lukemurraynz avatar

/identity-managed-identity

@2cc2455

Azure service-to-service (workload) identity: managed identity, user-assigned identity, Azure RBAC, passwordless Azure SDK connections, AKS workload identity, Azure DevOps Workload Identity Federation, GitHub Actions OIDC to Azure, and federated credential troubleshooting. Use when the user says "use managed identity", "passwordless Azure auth", "remove connection strings or keys", "federated credential", "workload identity federation", "GitHub Actions OIDC to Azure", "AKS workload identity", or "DefaultAzureCredential". Do NOT use for human sign-in, MFA, Conditional Access, or B2C / External ID consumer login ; use a human-identity (Entra) skill instead.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/identity-managed-identity

This session only. Nothing lands on disk.

CHANGELOG.md

≈2.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Changelog

All notable changes to the identity-managed-identity skill.

2.0.3 - 2026-08-25

Full-mode quality-improvement run (improve-skill v4.7.9): external re-verification against live ARM provider data, installed az CLI 2.89.1 help surface, current Microsoft Learn/GitHub docs, and owning-repo release pages (all checked 2026-08-25). All 14 built-in role GUIDs live-verified via az role definition list.

Fixed

  • Identity-selection contradiction removed. references/veteran-patterns.md said "Always prefer user-assigned for production", contradicting the default decision table (system-assigned for single-resource workloads). Now scoped to shared/stable-identity scenarios.
  • GitHub Actions login canonicalized to azure/login@v3 in references/veteran-patterns.md (was @v2 with ${{ secrets.* }}, inconsistent with github-actions-oidc.md's @v3 + ${{ vars.* }}). v3 released 2026-03-17; audience input verified on both majors.
  • Key Vault Bicep API pin updated 2024-11-01 → 2026-02-01 (newest stable verified against live ARM; Advisor flags older pins for retirement).
  • Stale currency date in SKILL.md body ("2026-05-10") aligned with frontmatter (last_verified: 2026-08-25).
  • ADO WIF reference completed: Entra-issuer ID-based subject format (<entra-prefix>/sc/<org-id>/<sc-id>) documented alongside the legacy sc:// shape with the automation attributes (workloadIdentityFederationSubject / Terraform equivalents); AADSTS70025 (no federated credentials configured) added to the error map.

Added

  • Flexible federated identity credentials (Preview) end-to-end guidance in SKILL.md: when to prefer over fixed subjects, doc-verified constraints (app-registration objects only; GitHub/GitLab/Terraform Cloud issuers; matches/eq/and operators; GitHub requires sub plus an immutable claim), and the az rest Microsoft Graph creation pattern (CLI/PowerShell/Terraform creation unsupported).
  • Wildcard-subject × immutable-ID pitfall note in references/github-actions-oidc.md: name-based wildcard trust silently stops matching for repos created/renamed after 2026-07-15.
  • Azure Verified Modules pointer in references/terraform-patterns.md as the landing-zone-grade alternative to primitive resources.
  • .NET developer-chain example in references/language-patterns.md aligned with the SKILL.md chain (added AzurePowerShellCredential).

Verification

  • Live ARM api-version sweep for every pinned resource type (roleAssignments@2022-04-01 and userAssignedIdentities@2024-11-30 confirmed still newest stable; other pins valid-stable under the standing verify-first rule).
  • Installed-binary ground truth: every az CLI command surface documented by the skill verified against az 2.89.1 help output.
  • azure-workload-identity v1.6.0 token-path claim re-verified against the release page (v1.6.1 maintenance-only).

2.0.2 - 2026-06-16

Added

  • Three-way credential decision table under "Credential selection": "Choosing between DefaultAzureCredential, ManagedIdentityCredential, and WorkloadIdentityCredential". Distinguishes the three by token-acquisition mechanism (IMDS endpoint vs projected federated OIDC token vs probing chain), with use-when / do-not-use-when columns and links to the Microsoft Learn API references for ManagedIdentityCredential and WorkloadIdentityCredential. Closes a gap where this guidance existed only spread across the default-decisions and environment tables.

2.0.1 - 2026-06-16

Quality-improvement pass: external factual re-verification (Microsoft Learn, official Azure SDK repos, GitHub & Azure DevOps docs, all checked 2026-06-16), correctness fixes, and structural alignment to the Cowork skill rubric. Deterministic validator green; rubric score 55 → 98 ("Excellent"); security scan PASS (bandit 0 findings).

Fixed (correctness)

  • .NET DefaultAzureCredential chain corrected. SharedTokenCacheCredential has been removed from the current chain and BrokerCredential is now the trailing credential. The CHANGELOG 2.0.0 enumeration was updated; references/language-patterns.md "twelve credential sources" corrected to "ten" with a note that the count/order is volatile.
  • Azure DevOps OIDC issuer. The legacy issuer path segment is the organization ID, not the tenant ID (https://vstoken.dev.azure.com/<organization-id>); newer service connections use the Entra issuer https://login.microsoftonline.com/<tenant-id>/v2.0. Corrected in SKILL.md and noted in references/azure-devops-wif.md.
  • AKS workload identity is not recreation-only. OIDC issuer and workload identity can be enabled in place on an existing cluster via az aks update --enable-oidc-issuer --enable-workload-identity; the prior "cannot be retrofitted without recreation" claim was removed.
  • Propagation guidance. Separated managed-identity (service principal) propagation from role-assignment propagation; role assignments are usually effective within ~5 minutes and up to ~30 minutes worst case (was an imprecise single "5-15 minutes").
  • JS managed identity uses the options-object form new ManagedIdentityCredential({ clientId }) (the string overload still works but is the older form).
  • Azure SQL: noted that Microsoft.Data.SqlClient 7.0 moved Entra-auth dependencies to the separate Microsoft.Data.SqlClient.Extensions.Azure package.
  • PostgreSQL microsoft-entra-admin create example now includes the required --resource-group and --server-name parameters.
  • AADSTS70021 clarified as the generic issuer-or-subject code (use 700211/700213 for the specific cause).

Added

  • GitHub immutable subject note: repositories created or renamed after 2026-07-15 default to repo:OWNER@OWNER-ID/REPO@REPO-ID:...; trust policies must match the format the repo actually issues.
  • Multi-identity ambiguity rule: more than one user-assigned identity (or user-assigned + system-assigned) without AZURE_CLIENT_ID is a configuration error, not a silent fall-back to system-assigned.
  • Ownership / approval / blast-radius guardrails: named owner per role assignment, named approver + review cadence for secret exceptions, explicit blast-radius statement, and the ~24h token-revocation lag.
  • Production credential gate added to the Quality Gate: deterministic credential in production with a startup check that fails fast on unexpected fallback.

Changed (structure / discoverability)

  • Description now carries quoted trigger phrases and an explicit "do NOT use … use a human-identity skill instead" exclusion.
  • Renamed sections to canonical headings: Do not use this skill when → When NOT to Use; Security guardrails → Guardrails.
  • Added a cowork: metadata block (category: automation); last_verified bumped to 2026-06-16.
  • Resource Directories section now lists standards/ and actions/ alongside references/.

Verification

  • Azure built-in role definition GUIDs (14), ARM/Bicep API versions (8), Cosmos native data-plane RBAC requirement, disableLocalAuth / allowSharedKeyAccess property names — all re-verified correct (Microsoft Learn / role catalog, 2026-06-16).
  • Federated credential subject formats, api://AzureADTokenExchange audience, GitHub/AKS OIDC issuers, AADSTS 700016/700211/700213/700223/700238/7000215, Service Bus / Event Hubs role names, Azure SQL contained-user requirement — re-verified correct.

2.0.0 - 2026-05-28

Phase 2 deep factual freshness audit applied. Azure.Identity / azure-identity credential chains re-verified against current package docs (2026-05-28).

Changed

  • DefaultAzureCredential chain description corrected. .NET Azure.Identity chain (current GA) contains ten credentials in order: EnvironmentCredential, WorkloadIdentityCredential, ManagedIdentityCredential, VisualStudioCredential, VisualStudioCodeCredential (requires the separate Azure.Identity.Broker package), AzureCliCredential, AzurePowerShellCredential, AzureDeveloperCliCredential, InteractiveBrowserCredential (disabled by default), BrokerCredential. Python azure-identity >= 1.14.0 changed the chain continuation policy: a developer credential that fails to acquire a token no longer halts the chain.
  • Production guidance reinforced: use specific credential types (WorkloadIdentityCredential, ManagedIdentityCredential(clientId=...)) explicitly in pod-identity or function/app-service scenarios; DefaultAzureCredential is for local development convenience only.
  • Federated credential subject formats re-verified for the three supported issuers: GitHub Actions, Azure DevOps Workload Identity Federation, and AKS workload identity. Subject string is exact-match. A mismatch produces a federation-rejection error - AADSTS70021 is the generic "no matching federated identity record" code (issuer or subject); use AADSTS700211 (issuer) and AADSTS700213 (subject) for the specific cause.

Added

  • AKS workload identity activation note: cluster requires --enable-workload-identity --enable-oidc-issuer at creation; cannot be retrofitted without recreating the cluster (or following the multi-step in-place enablement that may require a control-plane upgrade).
  • Identity propagation delay note: new managed identity assignments take 5-15 minutes to propagate; production smoke tests must not run immediately after IaC deploy.

Verification

  • Microsoft Learn - DefaultAzureCredential credential chain (.NET) (verified 2026-05-28).
  • Microsoft Learn - DefaultAzureCredential credential chain (Python) (verified 2026-05-28).
  • Microsoft Learn - Workload identity federation overview and supported scenarios (verified 2026-05-28).
  • Microsoft Learn - AKS workload identity (verified 2026-05-28).

1.0.0 - Initial release

  • Initial skill covering managed identity, federated credentials, AKS workload identity, GitHub Actions OIDC, Azure DevOps WIF, and Azure.Identity credential selection.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The skill is a professional toolset for managing Azure identities and promotes security best practices such as passwordless authentication. It includes utility scripts for diagnostic purposes. A low-risk surface for indirect prompt injection exists due to the processing of user-supplied identifiers into shell and cloud management commands.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
cowork
{
  "category": "automation"
}
metadata
{
  "last_verified": "2026-08-25"
}
Other metadata
compatibility
Azure CLI, Bicep or Terraform, Azure Identity SDK, Microsoft Entra workload identity federation

README badge

README badge for lukemurraynz/hve-agent-skills/identity-managed-identity