Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard

A development team is deploying a new microservices application using Azure Kubernetes Service (AKS). Each microservice needs to securely access Azure resources (e.g., Azure Key Vault, Azure Storage) using its own distinct identity, without embedding secrets directly into the pod configurations or using a single shared identity for all microservices. The solution must ensure that the identity is automatically provisioned and rotated by Azure. Which authentication mechanism should the team implement?

  1. AService principal with client secret stored in Kubernetes Secrets.
  2. BAzure AD Workload Identity for AKS.
  3. CKubernetes Secrets combined with Azure Key Vault.
  4. DSystem-assigned managed identity for the AKS cluster.
Show answer & explanation

Correct answer: B. Azure AD Workload Identity for AKS.

Azure AD Workload Identity for AKS enables Kubernetes pods to authenticate with Azure AD using a federated identity, allowing each pod to have its own identity without managing secrets. This aligns with the requirement for distinct identities per microservice and automatic provisioning/rotation.

Why the other options are wrong

  • A. Using a service principal with a client secret stored in Kubernetes Secrets requires manual secret management and rotation, which contradicts the requirement for automatic provisioning and rotation of identities.
  • C. While Kubernetes Secrets can store secrets from Azure Key Vault, this approach still involves managing secrets within Kubernetes and doesn't provide distinct, automatically managed identities for each pod.
  • D. A system-assigned managed identity for the AKS cluster provides a single identity for the entire cluster, not distinct identities for individual microservices/pods, and doesn't meet the 'each microservice needs its own distinct identity' requirement.

Azure AD Workload Identity for AKS

Azure AD Workload Identity for AKS allows Kubernetes pods to authenticate with Azure Active Directory using a federated identity, eliminating the need for client secrets and providing individual identities for workloads to access Azure resources securely.

  • Enables Kubernetes pods to authenticate with Azure AD.
  • Uses federated identity (OpenID Connect) with Azure AD.
  • Eliminates the need for managing client secrets for pods.
  • Provides granular, distinct identities for individual workloads.

Memory trick: Each pod's identity, automatically handled, no shared secrets.

More Implement Azure security questions