Skip to content

feat(credentials): add an explicit workload identity auth type for Azure Key Vault - #3485

Open
khrisrichardson wants to merge 1 commit into
chainloop-dev:mainfrom
khrisrichardson:feat/azure-key-vault-workload-identity
Open

khrisrichardson wants to merge 1 commit into
chainloop-dev:mainfrom
khrisrichardson:feat/azure-key-vault-workload-identity

Conversation

@khrisrichardson

@khrisrichardson khrisrichardson commented Sep 28, 2026 •

Copy link
Copy Markdown

Part of #3488.

The Azure Key Vault backend authenticated only with a service principal client secret: a long-lived credential that has
to be stored and rotated. AKS Workload Identity issues the pod a federated token for the same app registration instead.

Following the review of #3486, the operator now selects the mode explicitly. AzureKeyVault gains an auth_type enum:

  • AUTH_TYPE_CREDENTIALS (and AUTH_TYPE_UNSPECIFIED, so existing configurations do not change): the client secret
    is used, as before. A missing secret is still an error.
  • AUTH_TYPE_WORKLOAD_IDENTITY: the tenant and client ID are used with azidentity's WorkloadIdentityCredential,
    which reads the token that the workload identity webhook projects (AZURE_FEDERATED_TOKEN_FILE). Setting a client
    secret is an error, and so is a missing token file.
  • Undefined enum values are rejected by protovalidate (defined_only), and by the manager.

Chart: secretsBackend.azureKeyVault.authType (default AUTH_TYPE_CREDENTIALS). client_secret renders only for
AUTH_TYPE_CREDENTIALS. A secret set with workload identity, or an unknown authType, fails at template time. Chart
version bumped to 1.451.1.

To use workload identity, the pods need the azure.workload.identity/use: "true" label and the controlplane and cas
service accounts need the azure.workload.identity/client-id: <clientID> annotation. The README shows both. The label
goes through commonLabels, because controlplane.podLabels and cas.podLabels currently feed only the affinity
rules and never reach the pod template.

AI assistance: this PR was written with the help of Claude Code. Each commit carries an Assisted-by: Claude Code trailer.

@chainloop-platform

chainloop-platform Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

AI Session Checks — ⚠️ no AI session found

Missing AI Coding Sessions

This organization requires every PR to be backed by a Chainloop Trace AI coding session, and none was found for this one.

Please make sure the AI coding session evidence has been sent by the Chainloop CLI, or add the skip-ai-session label to this PR to bypass this check.

Learn more about Chainloop Trace.


Security Checks — ⚠️ 1 failing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top25 -
✅ Passed cwe-top26-40-cusp -

⚠️ iac-scan — 1 failing

Status Policy Messages
⚠️ Failed iac-misconfiguration Base64 High Entropy String in "deployment/chainloop/values.yaml" (error)

✅ security-context — no advisories

Nothing this change touches has a recorded security-fix history.

View security context ↗ · Security context documentation ↗

⏭️ 2 scans not applied

Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed

View attestation ↗


PR validation — ⚠️ 1 failing

Status Policy Material Messages
✅ Passed pr-description-required pr-info -
⚠️ Failed pr-min-approvals pr-info
✅ Passed pr-user-story-linked pr-info -

View attestation ↗


Powered by Chainloop and Chainloop Trace

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 7 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread deployment/chainloop/values.yaml Outdated
@jiparis

jiparis commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Thank you for this contribution. Before we can merge it, please fix these items:

  1. Sign your commits. The commits have a DCO sign-off, but GitHub shows them as not verified. Our contribution rules require signed commits (git commit -S -s). Refer to the GitHub signing guide.
  2. Bump the chart version. This PR changes the Helm chart source, so it must increase the patch version in deployment/chainloop/Chart.yaml. Rebase on main first, because the chart version on main changed after you opened this PR.
  3. Disclose AI assistance. If an AI tool helped you write any part of this PR, our AI contribution policy requires you to disclose it. Add an Assisted-by: trailer to each affected commit (for example Assisted-by: Claude Code), and state it in the PR description. Use the name of the tool that you used, not the name of the model.

@jiparis jiparis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please check my comment

…ure Key Vault

AzureKeyVault gains an auth_type enum. AUTH_TYPE_WORKLOAD_IDENTITY
authenticates as client_id through AKS Workload Identity, using the
federated token the workload identity webhook projects into the pod, so
no client secret is stored. AUTH_TYPE_CREDENTIALS keeps the service
principal client secret, and AUTH_TYPE_UNSPECIFIED is treated as
AUTH_TYPE_CREDENTIALS, so existing configurations do not change.

The operator must select workload identity explicitly. The manager
rejects AUTH_TYPE_CREDENTIALS without a client secret, so a forgotten
secret fails at startup instead of silently switching the authentication
method, and rejects AUTH_TYPE_WORKLOAD_IDENTITY with a client secret.

The chart exposes secretsBackend.azureKeyVault.authType and renders
client_secret only for AUTH_TYPE_CREDENTIALS. The README documents the
pod label and service account annotation that workload identity needs.

Assisted-by: Claude Code
Signed-off-by: Khris Richardson <khris.richardson@gmail.com>
@khrisrichardson
khrisrichardson force-pushed the feat/azure-key-vault-workload-identity branch from 9dc57b0 to b25743f Compare October 1, 2026 17:59
@khrisrichardson khrisrichardson changed the title feat(credentials): use AKS Workload Identity for Azure Key Vault when no client secret is configured feat(credentials): add an explicit workload identity auth type for Azure Key Vault Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants