All skills
lukemurraynz avatar

/identity-managed-identity

@2cc2455

Azure service-to-service (workload) identity: managed identity, user-assigned identity, Azure RBAC, passwordless Azure SDK connections, AKS workload identity, Azure DevOps Workload Identity Federation, GitHub Actions OIDC to Azure, and federated credential troubleshooting. Use when the user says "use managed identity", "passwordless Azure auth", "remove connection strings or keys", "federated credential", "workload identity federation", "GitHub Actions OIDC to Azure", "AKS workload identity", or "DefaultAzureCredential". Do NOT use for human sign-in, MFA, Conditional Access, or B2C / External ID consumer login ; use a human-identity (Entra) skill instead.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/identity-managed-identity

This session only. Nothing lands on disk.

referenceslanguage-patterns.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Language Patterns for Azure Identity

Use explicit production credentials and reuse credential instances. These examples are minimal patterns; adapt dependency injection and configuration to the application framework.

.NET

App Service / Container Apps / VM (system- or user-assigned managed identity):

using Azure.Core;
using Azure.Identity;
using Azure.Storage.Blobs;

TokenCredential credential = builder.Environment.IsDevelopment()
    ? new ChainedTokenCredential(
        new AzureDeveloperCliCredential(),  // azd auth login
        new VisualStudioCredential(),
        new AzureCliCredential(),
        new AzurePowerShellCredential())
    : new ManagedIdentityCredential();

builder.Services.AddSingleton(credential);
builder.Services.AddSingleton(_ => new BlobServiceClient(
    new Uri("https://<account>.blob.core.windows.net"),
    credential));

For user-assigned managed identity:

var credential = new ManagedIdentityCredential(
    ManagedIdentityId.FromUserAssignedClientId(configuration["AZURE_CLIENT_ID"]));

AKS workload identity with developer fallback (preferred pattern for AKS + azd projects):

Use a single ChainedTokenCredential - no environment check needed. WorkloadIdentityCredential succeeds in AKS when AZURE_FEDERATED_TOKEN_FILE is injected by the mutating webhook; it fails fast on a developer workstation, and the chain falls through to the azd or CLI credential.

// Register once and share across all SDK clients.
TokenCredential credential = new ChainedTokenCredential(
    new WorkloadIdentityCredential(),    // AKS production
    new AzureDeveloperCliCredential(),   // azd auth login (local dev)
    new AzureCliCredential());           // az login fallback

builder.Services.AddSingleton<TokenCredential>(credential);
builder.Services.AddSingleton(_ => new BlobServiceClient(
    new Uri("https://<account>.blob.core.windows.net"),
    credential));

Do not use DefaultAzureCredential in production for AKS deployments. It probes ten credential sources (the exact count and order have changed across Azure.Identity releases, do not hard-code an assumption about it) and can silently fall through to an unexpected identity (for example, the deploying service principal's AzureCliCredential) if workload identity is misconfigured, making auth failures hard to diagnose. WorkloadIdentityCredential at the head of an explicit chain fails loudly when the AKS mutating webhook has not injected the expected env vars.

Python

from azure.identity import ManagedIdentityCredential
from azure.storage.blob import BlobServiceClient

credential = ManagedIdentityCredential()
client = BlobServiceClient(
    account_url="https://<account>.blob.core.windows.net",
    credential=credential,
)

For AKS workload identity:

from azure.identity import WorkloadIdentityCredential
credential = WorkloadIdentityCredential()

For local development only:

from azure.identity import ChainedTokenCredential, AzureCliCredential, VisualStudioCodeCredential
credential = ChainedTokenCredential(VisualStudioCodeCredential(), AzureCliCredential())

Node.js / TypeScript

import { ManagedIdentityCredential } from "@azure/identity";
import { BlobServiceClient } from "@azure/storage-blob";

// Pass { clientId } for a user-assigned identity; the bare string overload still works but the options object is the current form.
const credential = new ManagedIdentityCredential({ clientId: process.env.AZURE_CLIENT_ID });
const client = new BlobServiceClient(
  "https://<account>.blob.core.windows.net",
  credential,
);

For AKS workload identity:

import { WorkloadIdentityCredential } from "@azure/identity";
const credential = new WorkloadIdentityCredential();

Java

import com.azure.identity.ManagedIdentityCredential;
import com.azure.identity.ManagedIdentityCredentialBuilder;
import com.azure.storage.blob.BlobServiceClient;
import com.azure.storage.blob.BlobServiceClientBuilder;

ManagedIdentityCredential credential = new ManagedIdentityCredentialBuilder()
    .clientId(System.getenv("AZURE_CLIENT_ID"))
    .build();

BlobServiceClient client = new BlobServiceClientBuilder()
    .endpoint("https://<account>.blob.core.windows.net")
    .credential(credential)
    .buildClient();

Rules

  • Do not log tokens, connection strings, or authorization headers.
  • Do not create credential instances per request.
  • Do not mix production managed identity with local developer fallback in the same production runtime.
  • Keep local developer identity permissions separate from workload identity permissions.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The skill is a professional toolset for managing Azure identities and promotes security best practices such as passwordless authentication. It includes utility scripts for diagnostic purposes. A low-risk surface for indirect prompt injection exists due to the processing of user-supplied identifiers into shell and cloud management commands.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
cowork
{
  "category": "automation"
}
metadata
{
  "last_verified": "2026-08-25"
}
Other metadata
compatibility
Azure CLI, Bicep or Terraform, Azure Identity SDK, Microsoft Entra workload identity federation

README badge

README badge for lukemurraynz/hve-agent-skills/identity-managed-identity