Access Azure Key Vault from a Local Kubernetes Cluster with Azure Arc Workload Identity

Access Azure Key Vault from a Local Kubernetes Cluster with Azure Arc Workload Identity

In the last post, we connected a local Kubernetes cluster to Azure using Azure Arc so that we could manage it from the Azure portal.

Which is cool, but if all we do is stare at our cluster from Azure, we are missing the fun part.

What I really want from this setup is the ability to run workloads locally that can authenticate to Azure resources in the same way they would in a “real” environment, without me having to stuff secrets into config files or pass credentials around by hand.
12 minutes to read
Connecting a Local Kubernetes Cluster to Azure Using Azure Arc

Connecting a Local Kubernetes Cluster to Azure Using Azure Arc

Over the last few years, my focus at work has migrated away from Intune and device management to software engineering and the management of cloud native technologies.

This, to the surprise of no one, has been a steep learning curve. One of the big challenges I’ve faced is how to test and develop applications locally in an environment that mimics the production environments that the software will eventually run in.
7 minutes to read
Access Graph resources across tenants without secrets or certificates!

Access Graph resources across tenants without secrets or certificates!

Microsoft has recently announced a new feature that allows us to use managed identities to authenticate across tenants. This is a big deal, and opens up a new secure way of managing multiple tenants in Azure.

One of the biggest security concerns facing developers today is credential leakage and features like this help alleviate the risk of potentially leaving secrets in source control by removing the need for them entirely!

In this post I’ll show you how to set this up to authenticate to a second tenant in an Azure function app, and how to use it to call the Microsoft Graph API!
10 minutes to read
Authenticate to Graph in Azure Functions with Managed Identites (Part 1)

Authenticate to Graph in Azure Functions with Managed Identites (Part 1)

When creating Azure Functions, there has always been a way to create and use “managed identities” to securely and simply access resources within the resource group that the function app resides.

With a little bit of PowerShell and a basic understanding of how API permissions are programmatically applied, we can use the managed identity to access Graph without needing to store credentials anywhere! Secure AND cool, right?

7 minutes to read