Description
Static credentials stored by a Container App for Key Vault or Storage access can be exposed or missed during replacement. Managed identity lets Azure manage authentication credentials and supports access to compatible services without deploying an application secret. Its absence alone does not establish credential exposure.
Potential impact
- Credentials stored in environment variables or configuration files can be exposed.
- Missed replacement or revocation can leave credentials usable for a long time.
- Tracking and minimizing each application’s permissions can become harder.
Remediation
Configure a SystemAssigned or UserAssigned ID in the Container App identity block according to lifecycle and operational needs. Grant only required RBAC roles on target resources and configure the application to use managed identity tokens. Verify operation before removing and revoking replaced secrets.
Examples
This example adds a system-assigned managed identity to a Container App. Configure the referenced environment and resource group, target permissions and application token use separately.
Before
resource "azurerm_container_app" "example" {
name = "example-app"
container_app_environment_id = azurerm_container_app_environment.example.id
resource_group_name = azurerm_resource_group.example.name
revision_mode = "Single"
template {
container {
name = "app"
image = "mcr.microsoft.com/k8se/quickstart:latest"
cpu = 0.25
memory = "0.5Gi"
}
}
}
After
resource "azurerm_container_app" "example" {
name = "example-app"
container_app_environment_id = azurerm_container_app_environment.example.id
resource_group_name = azurerm_resource_group.example.name
revision_mode = "Single"
identity {
type = "SystemAssigned"
}
template {
container {
name = "app"
image = "mcr.microsoft.com/k8se/quickstart:latest"
cpu = 0.25
memory = "0.5Gi"
}
}
}
The after example enables a SystemAssigned identity. Attaching an identity does not itself grant target permissions or automatically make the application use that authentication method.