Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard

A company is developing a microservices-based application using Azure Kubernetes Service (AKS). Each microservice needs to securely access specific secrets stored in Azure Key Vault. The solution must ensure that only authorized microservices can retrieve their respective secrets. Which approach should be implemented?

  1. AStore secrets directly in AKS configuration maps and mount them as volumes.
  2. BEnable Azure AD Pod Identity on AKS and grant access to Key Vault for specific pods.
  3. CImplement client-side encryption for all secrets before storing them in AKS.
  4. DUse environment variables to store Key Vault access credentials for each microservice.
Show answer & explanation

Correct answer: B. Enable Azure AD Pod Identity on AKS and grant access to Key Vault for specific pods.

Azure AD Pod Identity (or its successor, Azure Workload Identity) allows Kubernetes pods to access cloud resources securely with Azure Active Directory. By assigning a managed identity to specific pods and granting that identity access to specific Key Vault secrets, only authorized microservices (pods) can retrieve their secrets, ensuring fine-grained access control.

Why the other options are wrong

  • A. Storing secrets directly in AKS configuration maps is insecure as they are stored unencrypted.
  • C. Client-side encryption helps with data at rest, but doesn't solve the problem of *authorized access* to secrets from Key Vault by different microservices.
  • D. Using environment variables for credentials is insecure, as they can be easily exposed.

Azure AD Pod Identity (or Workload Identity)

A mechanism in Azure Kubernetes Service that allows Kubernetes pods to access Azure resources securely using Azure Active Directory identities (managed identities).

  • Enables identity-based access for pods
  • Replaces the need for explicit credentials in code
  • Provides granular access control for Azure resources

Memory trick: Pod Identity: Each pod gets its own ID card to the vault.

More Implement Azure security questions