Managed identities
The identity the platform gives each app, function namespace and container instance, so a workload can sign in without holding a credential.
A managed identity is a principal the platform creates for a workload. It lets the workload sign in to the platform as itself — to read its secrets, for example — without anyone handing it a password or key.
Which resources have one
| Resource | Identity |
|---|---|
| App | One per app, shared by all its slots |
| Function namespace | One per function namespace, shared by every function in it |
| Container instance | One per instance, shared by all its components |
The platform also gives each S3 storage account an identity for its own use.
The identity is created with the resource and deleted when the resource is deleted.
What it is
Behind each identity is a client in the platform's identity provider, named mi- followed by an
ID of the resource. Role assignments do not use that name but the identity's principal ID,
which is also what a token issued to the workload carries as its subject. Both are shown on the
Managed Identity card on the resource's Overview.
In role assignments a managed identity is a service principal, and the Access Control tabs label it Service.
It starts with no access
A new identity holds no role. Give it exactly what the workload needs — usually Secrets Reader on the vaults it reads — see Give a managed identity a role.
Two things assign a role for you, using your own permissions: creating or changing a container instance whose containers reference a vault, and deploying a blueprint. Both give the workload's identity Secrets Reader on the vault — see Give a workload access to a vault.
How a workload uses it
The platform itself uses the identity to fetch a workload's secrets when its pods start — see Use secrets in workloads. The workload's own code can use it as well: the platform tells each container where to ask for a token, and the pod proves which workload it is. See Use a managed identity in code.
When the resource is deleted
Deleting the resource deletes its identity. Role assignments that named the identity are not removed with it; remove them where you made them. A resource created again under the same name gets a new identity with a new principal ID, so its roles must be assigned again.