All skills
lukemurraynz avatar

/identity-managed-identity

@2cc2455

Azure service-to-service (workload) identity: managed identity, user-assigned identity, Azure RBAC, passwordless Azure SDK connections, AKS workload identity, Azure DevOps Workload Identity Federation, GitHub Actions OIDC to Azure, and federated credential troubleshooting. Use when the user says "use managed identity", "passwordless Azure auth", "remove connection strings or keys", "federated credential", "workload identity federation", "GitHub Actions OIDC to Azure", "AKS workload identity", or "DefaultAzureCredential". Do NOT use for human sign-in, MFA, Conditional Access, or B2C / External ID consumer login ; use a human-identity (Entra) skill instead.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/identity-managed-identity

This session only. Nothing lands on disk.

standardsidentity-selection.md

≈694 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Identity Selection Standard

Decision matrix

Scenario Identity type Reason
One Azure app accesses one or a small set of resources System-assigned managed identity Simple lifecycle and least operational overhead
Multiple Azure apps need identical access User-assigned managed identity One stable principal and reusable role assignments
Blue/green deployments, deployment slots, or resource recreation User-assigned managed identity Identity survives workload replacement
AKS pod accesses Azure resources Microsoft Entra Workload ID + user-assigned managed identity No secrets in pods and no deprecated pod-managed identity
Azure DevOps deploys to Azure Azure Resource Manager service connection with Workload Identity Federation No service principal secret rotation
GitHub Actions deploys to Azure GitHub OIDC federated credential No long-lived Azure credential in GitHub secrets
Local developer runs app Developer tool credential chain Human developer identity stays separate from workload identity
Cross-tenant or external workload federation App registration or managed identity federated credential Requires explicit issuer/subject/audience trust

System-assigned managed identity

Use when the workload has a single, clear lifecycle and the identity should be deleted with the resource.

resource app 'Microsoft.Web/sites@2024-04-01' = {
  name: app_name
  location: location
  identity: {
    type: 'SystemAssigned'
  }
}

User-assigned managed identity

Use when the identity must be stable, shared, pre-provisioned, or bound explicitly through AZURE_CLIENT_ID.

resource identity 'Microsoft.ManagedIdentity/userAssignedIdentities@2024-11-30' = {
  name: 'id-${service_name}-${environment_name}'
  location: location
}

For production workloads with user-assigned identity, configure the client ID explicitly:

AZURE_CLIENT_ID=<user-assigned-managed-identity-client-id>

Workload identity federation

Use when the workload runs outside the direct Azure managed identity runtime or needs a projected OIDC token. Common cases are AKS, Azure DevOps, and GitHub Actions.

Federated credential values must match exactly:

  • issuer
  • subject
  • audience, normally api://AzureADTokenExchange for Azure workload identity federation

Anti-patterns

  • Sharing one identity across unrelated applications or environments.
  • Using an app registration secret because federation setup is unfamiliar.
  • Assigning roles to the wrong principal because display names look similar.
  • Depending on local developer permissions to prove production access will work.
  • Creating role assignments manually without capturing them in IaC.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The skill is a professional toolset for managing Azure identities and promotes security best practices such as passwordless authentication. It includes utility scripts for diagnostic purposes. A low-risk surface for indirect prompt injection exists due to the processing of user-supplied identifiers into shell and cloud management commands.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
cowork
{
  "category": "automation"
}
metadata
{
  "last_verified": "2026-08-25"
}
Other metadata
compatibility
Azure CLI, Bicep or Terraform, Azure Identity SDK, Microsoft Entra workload identity federation

README badge

README badge for lukemurraynz/hve-agent-skills/identity-managed-identity