Skip to content
Stackship documentation Svenska

Managed identitiesUsers

Give a managed identity a role

Find a workload's principal ID and assign its managed identity a role on a resource, a resource group or a boundary.

Requires: rbac/members/write

A workload can do only what its managed identity's roles allow. Assigning it a role works like assigning one to a person — see Role assignments for who may do it — except that you find the identity by its principal ID, not by its name.

Find the principal ID

  1. In the portal at https://portal.example.com, open the app, function namespace or container instance.
  2. On its Overview, the Managed Identity card shows the Principal ID. Copy it.

The Client ID on the same card, mi-…, is not the principal ID and does not work in role assignments. The card is shown only to people who may read the resource — apps/read for an app and also for a function namespace, containerinstance/read for a container instance — and its contents need managedidentities/read.

With the CLI, stsh identity list -g <resource-group> -o json lists the identities in a resource group with their principalId.

Assign a role on a resource

  1. Open the resource the workload needs — a vault, say — and its Access Control tab.
  2. Choose Add role assignment.
  3. Paste the principal ID into the search field. The identity appears under the resource's name, labelled Service. Searching by the resource's name looks only at the first 20 managed identities on the platform, so it usually misses; use the principal ID.
  4. Pick the Role — for a vault, Secrets Reader — and choose Add assignment.

To give the identity a role on the whole boundary, do the same on the Access Control tab of the boundary's own page.

Assign a role with the CLI

The CLI can assign at any scope, a resource group included:

bash
stsh iam assignment create \
  --set principalId=<principal-id> \
  --set principalType=ServicePrincipal \
  --set roleDefinitionId=<role-id> \
  --set scope=/boundaries/<boundary-id>/resourcegroups/web

stsh iam role list shows the role IDs.

Which identities you can assign

You can give roles to the identities of workloads in any boundary of the same tenant. An identity from another tenant's boundary needs a boundary trust — see Tenants and guests.