[Knowledge] managed-identity: ## Advisory Notes — Stage 1: Managed Identity - **[Architec...
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 85/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- azure
- Domain
- documentation
Research direction
Open knowledge/services/managed-identity.md and review the existing Stage 1 Managed Identity guidance. Add the supplied Advisory Notes covering the shared-identity trade-off, least-privilege isolation, and resource-lock security concern. Done means the notes are present in the knowledge file with the requested headings and formatting.
Written by the indexing model from the issue text.
Description
Knowledge Contribution
Type: Pitfall
File: knowledge/services/managed-identity.md
Context
Advisory Notes — Stage 1: Managed Identity
-
[Architectural Trade-off] A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.
-
[Security] No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev
Rationale
Advisory Notes — Stage 1: Managed Identity
-
[Architectural Trade-off] A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.
-
[Security] No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev
Content to Add
## Advisory Notes — Stage 1: Managed Identity
- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permi
Source
Build advisory review
- Dominant language
- Python
- Stars
- 41
- Forks
- 10
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Azure/az-prototype
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
Azure/az-prototype#71 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 70/100
Azure/az-prototype#66 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
Azure/az-prototype#65 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
Azure/az-prototype#64 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Azure/az-prototype#63 ·
All issues in Azure/az-prototype
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100