[Knowledge] container-app-api: ## Advisory Notes — Stage 1: Managed Identity - **[Architec...
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 68/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- azure, python, terraform
- Domain
- cloud, documentation, security
Research direction
Create knowledge/services/container-app-api.md and use the issue's eight required sections as the outline. Start by reviewing the Build advisory review content and the requested Terraform, Bicep, and application-code coverage. Done means the new file includes Description, usage guidance, POC defaults, implementation patterns, pitfalls, and production backlog items.
Written by the indexing model from the issue text.
Description
Knowledge Contribution
Type: New service
File: knowledge/services/container-app-api.md
Status: NEW FILE — this knowledge file does not exist yet and must be created
Context
Advisory Notes — Stage 1: Managed Identity
-
[Architectural Trade-off] A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.
-
[Security] No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev
Rationale
Advisory Notes — Stage 1: Managed Identity
-
[Architectural Trade-off] A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.
-
[Security] No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev
Content to Add
## Advisory Notes — Stage 1: Managed Identity
- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permi
Source
Build advisory review
Required Knowledge File Sections
The new knowledge file MUST include ALL of these sections:
- Description (one-line summary)
- When to Use (scenarios and selection criteria)
- POC Defaults (default SKU, tier, configuration)
- Terraform Patterns (azapi_resource with RBAC)
- Bicep Patterns (ARM template resources)
- Application Code (Python, C#, Node.js — where applicable)
- Common Pitfalls (deployment failures, misconfigurations)
- Production Backlog Items (what changes for production)
- Dominant language
- Python
- Stars
- 41
- Forks
- 10
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Azure/az-prototype
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
Azure/az-prototype#71 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 70/100
Azure/az-prototype#66 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
Azure/az-prototype#65 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
Azure/az-prototype#64 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Azure/az-prototype#63 ·
All issues in Azure/az-prototype
Similar issues
-
documentation help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
simonw/sqlite-utils#872 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100