[Knowledge] frontend-app: ## Advisory Notes — Stage 1: Managed Identity - **[Architec...
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 68/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Quiet
- Domain
- cloud, documentation, infrastructure, security
Research direction
Create knowledge/services/frontend-app.md, using the issue's required sections and the build advisory review as the source. Cover the requested managed identity guidance, Terraform and Bicep patterns, applicable Python, C#, and Node.js application code, pitfalls, and production backlog items; done means all eight sections are present and documented.
Written by the indexing model from the issue text.
Description
Knowledge Contribution
Type: New service
File: knowledge/services/frontend-app.md
Status: NEW FILE — this knowledge file does not exist yet and must be created
Context
Advisory Notes — Stage 1: Managed Identity
-
[Architectural Trade-off] A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.
-
[Security] No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev
Rationale
Advisory Notes — Stage 1: Managed Identity
-
[Architectural Trade-off] A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.
-
[Security] No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev
Content to Add
## Advisory Notes — Stage 1: Managed Identity
- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permi
Source
Build advisory review
Required Knowledge File Sections
The new knowledge file MUST include ALL of these sections:
- Description (one-line summary)
- When to Use (scenarios and selection criteria)
- POC Defaults (default SKU, tier, configuration)
- Terraform Patterns (azapi_resource with RBAC)
- Bicep Patterns (ARM template resources)
- Application Code (Python, C#, Node.js — where applicable)
- Common Pitfalls (deployment failures, misconfigurations)
- Production Backlog Items (what changes for production)
- Dominant language
- Python
- Stars
- 41
- Forks
- 10
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Azure/az-prototype
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
Azure/az-prototype#71 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 70/100
Azure/az-prototype#66 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
Azure/az-prototype#65 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
Azure/az-prototype#64 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Azure/az-prototype#63 ·
All issues in Azure/az-prototype
Similar issues
-
bug ci good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
documentation
Difficulty 2/5 Half a day Newbie friendliness 62/100
inmanta/inmanta-core#10835 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
sponsored
Difficulty 2/5 1-3 hours Newbie friendliness 65/100