IDToken - Azure
Azure supports federation with external identity providers through a feature called Federated Credentials. Using this, you can allow identities managed by an external identity provider to perform actions in your Azure subscription.
In this scenario the external identity provider is Concourse and the identities are teams/pipelines/jobs. This means you are able to grant a specific pipeline or job permission to perform actions in Azure (like deploying something), all without managing service principal secrets or dealing with long-lived credentials.
Create App Registration
First, create an EntraID App Registration along with the service principal that represents it. This app registration and its service principal are what your pipeline will act as once it exchanges a Concourse-issued JWT for an Azure token.
Create Federated Credential
Next, create a federated credential for the app registration you just created.
- Set
issuerto the external URL of your Concourse server (or the--oidc-issuer-urlif you're using a separate OIDC issuer - see Configuring a Separate OIDC Issuer). - Set
subjecttomain/deploy-to-azure. If you use thesubject_scopesetting to change the contents of your sub-claim, change this value here accordingly. - For
audiences, you can choose any string you like, but using a value likeapi://AzureADTokenExchangeis recommended.
Note
You have to use the same string later in the configuration of your idtoken var source.
Info
This will allow ONLY that specific pipeline (and any instanced versions of it) to obtain a token for this identity using a JWT.
Assign Role Permissions
Now, assign the identity of the app registration an RBAC role that defines what it's allowed to do in your Azure subscription.
Use within the Pipeline
Your pipeline can now use the az CLI to log in to Azure using a JWT issued by Concourse, via
az login's federated-token support: