[Knowledge] private-endpoints: ## Advisory Notes — Stage 1: Managed Identity - **[Architec...
- Dominant language
- Python
- Stars
- 41
- Forks
- 10
- PR merge metrics
- No merged PRs in 30d
Description
## Knowledge Contribution
**Type:** Pitfall
**File:** `knowledge/services/private-endpoints.md`
### Context
## Advisory Notes — Stage 1: Managed Identity
- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.
- **[Security]** No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev
### Rationale
## Advisory Notes — Stage 1: Managed Identity
- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.
- **[Security]** No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev
### Content to Add
```
## Advisory Notes — Stage 1: Managed Identity
- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permi
```
### Source
Build advisory review
Contributor guide
No contributing guide indexed for this repository
Research direction
Open knowledge/services/private-endpoints.md and review the surrounding knowledge entries before adding the supplied Advisory Notes for Stage 1: Managed Identity. Preserve the existing Markdown structure and include the complete content from the issue. Done means the advisory section is present in that file with its architectural trade-off and security notes intact.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- cloud, documentation, security
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 88/100