Uploaded image for project: 'Ansible Strategy'
  1. Ansible Strategy
  2. ANSTRAT-631

Phase 1: Azure Managed Identity

XMLWordPrintable

    • False
    • False
    • 0% To Do, 100% In Progress, 0% Done

      Background

      The Azure collection currently supports username/password and service principal authentication. These both require special configuration or maintenance and limit a managed app’s ability to maintain a seamless experience. If managed applications could request managed identities at deployment, then managed applications could automate against an Azure tenancy without the need for an AD account or service principal credential that expire and require manual management after deployment improving the overall experience.

      This may not be something that is technically feasible unless the automation is actually running as a managed application.

      Business Impact: Ensuring customers Azure resource management best practices, and ease the management and setup of credentials when automating against Azure resources.

      Story

      As an Ansible on Clouds customer I can write playbooks and configure tasks that can request managed identities from Azure so that automations against Azure resources can use it as a credential for automation delivery. This will allow me to use Azure's recommended approach for application security and remove the need to create numerous Service Principals that perform the same operation but in a less manageable way.

            mferrari@redhat.com Massimo Ferrari
            sharwell@redhat.com Scott Harwell
            Emily Bock, Stephen Fulmer
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: