[Identity] Support Azure Arc user-assigned managed identity (UAMI) via MSAL
Maintainer thường phản hồi trong vòng 1 ngày
@kashifkhan đang làm issue này rồi.
Từ ngày 24/8/2026.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
Background
MSAL Python now supports acquiring tokens for user-assigned managed identities (UAMI) on Azure Arc (MSAL Python 1.38.0). Historically Azure Arc only supported system-assigned managed identity (SAMI). This issue tracks enabling Arc UAMI in azure-identity (ManagedIdentityCredential and DefaultAzureCredential), for both sync and async.
azure-identity has two independent managed-identity stacks for Arc, and they need different work:
Current behavior
- Sync (MSAL)
AzureArcCredential(azure/identity/_credentials/azure_arc.py) extendsMsalManagedIdentityClientand delegates tomsal.ManagedIdentityClient(acquire_token_for_client,msal.UserAssignedManagedIdentity/SystemAssignedManagedIdentity). UAMI-on-Arc is gated by MSAL, so amsalversion bump is sufficient here. - Async (native, no MSAL)
AzureArcCredential(azure/identity/aio/_credentials/azure_arc.py) extendsAsyncManagedIdentityBaseand drives the customAsyncManagedIdentityClient(aio/_internal/managed_identity_client.py, built onbuild_async_pipeline) plusArcChallengeAuthPolicy. MSAL Python is sync-only, so the async path cannot delegate to MSAL and will NOT inherit Arc UAMI from the dependency bump — it needs its own code change. - Explicit block:
_get_requestin_credentials/azure_arc.py(imported and used by the async credential) raisesClientAuthenticationError("User assigned managed identities are not supported by Azure Arc...")wheneveridentity_configis set.ManagedIdentityClientBase.__init__foldsclient_idintoself._identity_config, so this trips for client id, object id, and resource id. This block is effectively async-only now (the sync credential goes through MSAL and no longer calls_get_request).
Net effect: sync needs only a dependency uptake; async (native) needs the explicit block removed, the id sent as the correct query parameter, and behavior aligned with the MSAL/sync path.
Scope of work
Sync (MSAL)
- Bump
msaldependency to>= 1.38.0. - Verify Arc UAMI token acquisition (client id, and resource/object id as supported).
Async (native, no MSAL)
- Remove the explicit UAMI-on-Arc block in
_get_request(_credentials/azure_arc.py). - Send the user-assigned id as the correct Arc query parameter — map the
resource_idkey to the Arc param name (mi_res_id/msi_res_id);client_id/object_idnames are already correct. Confirm theapi-version(currently2020-06-01) honors UAMI and matches what MSAL sends on the sync side. - (Alternative) Consider delegating the async path to MSAL via
run_in_executorfor behavioral parity with sync, instead of maintaining the native implementation (larger change; adds thread-pool overhead). - Update async tests (e.g.
test_azure_arc*/ aio variants) that currently assert Arc UAMI is rejected.
Shared
- Keep sync (MSAL) and async (native) consistent on query-param names, api-version, and endpoint handling.
- Update CHANGELOG (and README if it documents Arc as system-assigned-only).
Key references
sdk/identity/azure-identity/azure/identity/_credentials/azure_arc.pysdk/identity/azure-identity/azure/identity/aio/_credentials/azure_arc.pysdk/identity/azure-identity/azure/identity/aio/_internal/managed_identity_client.pysdk/identity/azure-identity/azure/identity/_internal/managed_identity_client.pysdk/identity/azure-identity/azure/identity/_internal/msal_managed_identity_client.py
- Ngôn ngữ chính
- Python
- Star
- 5.6k
- Fork
- 3.4k
- Merge trung bình
- 2 ngày 1 phút
- Pull request đã merge (30 ngày)
- 218
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của Azure/azure-sdk-for-python
-
Evaluation Service Attention
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Azure/azure-sdk-for-python#49190 · 1 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Update CODEOWNERSĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
Azure/azure-sdk-for-python#49183 · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Evaluation Service Attention
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Azure/azure-sdk-for-python#49153 · 1 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Search Service Attention
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
Azure/azure-sdk-for-python#48555 · 1 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Azure.Core customer-reported feature-request needs-team-attention
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Azure/azure-sdk-for-python#47186 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của Azure/azure-sdk-for-python
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
kornia/kornia#5263 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Metadata correction for W16-5400Đang mởapproved correction metadata
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
acl-org/acl-anthology#10133 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
BasedHardware/omi#20084 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug needs-acceptance wg/evaluation-quality
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
vllm-project/semantic-router#4424 ·
Maintainer thường phản hồi trong vòng 1 ngày