Container App has no managed identity configured

Use managed identity for supported Azure services to reduce a Container App’s reliance on static credentials.

Description

Static credentials stored by a Container App for Key Vault or Storage access can be exposed or missed during replacement. Managed identity lets Azure manage authentication credentials and supports access to compatible services without deploying an application secret. Its absence alone does not establish credential exposure.

Potential impact

  • Credentials stored in environment variables or configuration files can be exposed.
  • Missed replacement or revocation can leave credentials usable for a long time.
  • Tracking and minimizing each application’s permissions can become harder.

Remediation

Configure a SystemAssigned or UserAssigned ID in the Container App identity block according to lifecycle and operational needs. Grant only required RBAC roles on target resources and configure the application to use managed identity tokens. Verify operation before removing and revoking replaced secrets.

Examples

This example adds a system-assigned managed identity to a Container App. Configure the referenced environment and resource group, target permissions and application token use separately.

Before

hcl
resource "azurerm_container_app" "example" {
  name                         = "example-app"
  container_app_environment_id = azurerm_container_app_environment.example.id
  resource_group_name          = azurerm_resource_group.example.name
  revision_mode                = "Single"

  template {
    container {
      name   = "app"
      image  = "mcr.microsoft.com/k8se/quickstart:latest"
      cpu    = 0.25
      memory = "0.5Gi"
    }
  }
}

After

hcl
resource "azurerm_container_app" "example" {
  name                         = "example-app"
  container_app_environment_id = azurerm_container_app_environment.example.id
  resource_group_name          = azurerm_resource_group.example.name
  revision_mode                = "Single"

  identity {
    type = "SystemAssigned"
  }

  template {
    container {
      name   = "app"
      image  = "mcr.microsoft.com/k8se/quickstart:latest"
      cpu    = 0.25
      memory = "0.5Gi"
    }
  }
}

The after example enables a SystemAssigned identity. Attaching an identity does not itself grant target permissions or automatically make the application use that authentication method.

References