Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesHard

A DevOps team is responsible for managing several Azure Kubernetes Service (AKS) clusters across different environments (Dev, Test, Prod). They need a secure and auditable way for Azure Pipelines to connect to these AKS clusters to deploy applications. The connection must not expose sensitive credentials directly in the pipeline definition and should leverage Azure Active Directory (AAD) authentication for identity management. Which type of Azure DevOps service connection should be used?

  1. AGeneric service connection
  2. BExternal Git service connection
  3. CKubernetes service connection (KubeConfig)
  4. DAzure Resource Manager service connection (Workload Identity federation)
Show answer & explanation

Correct answer: D. Azure Resource Manager service connection (Workload Identity federation)

An Azure Resource Manager service connection configured with Workload Identity federation is the most secure and recommended way for Azure Pipelines to connect to AKS. It allows the pipeline to authenticate with Azure AD and obtain an access token to interact with AKS, without needing to store or manage service principal credentials directly in Azure DevOps. This leverages Azure's native identity management for enhanced security and auditability.

Why the other options are wrong

  • A. Generic service connections are too broad and don't provide the specific, secure AAD-based integration required for AKS.
  • B. External Git service connections are for connecting to source code repositories, not for deploying to AKS clusters.
  • C. While a Kubernetes service connection can use KubeConfig, this often involves storing a service account token or KubeConfig file, which is less secure than AAD Workload Identity federation for Azure-native environments.

Azure RM Service Connection with Workload Identity

An Azure Resource Manager service connection configured with Workload Identity federation enables secure, credential-less authentication for Azure Pipelines to interact with Azure resources like AKS, leveraging Azure AD.

  • Securely connects Azure Pipelines to Azure resources.
  • Uses Workload Identity federation for credential-less authentication.
  • Leverages Azure Active Directory for identity.
  • Recommended for AKS deployments in Azure DevOps.

Memory trick: Workload Identity: Your Pipeline's Password-less Pass to AKS.

More Design and implement pipelines questions