Azure / Azure/az-prototype

[Knowledge] container-app-api: ## Advisory Notes — Stage 1: Managed Identity - **[Architec...

Open
#56 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
41
Forks
10
PR merge metrics
No merged PRs in 30d

Description

## Knowledge Contribution

**Type:** New service
**File:** `knowledge/services/container-app-api.md`
**Status:** NEW FILE — this knowledge file does not exist yet and must be created

### Context
## Advisory Notes — Stage 1: Managed Identity

- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.

- **[Security]** No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev

### Rationale
## Advisory Notes — Stage 1: Managed Identity

- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.

- **[Security]** No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev

### Content to Add
```
## Advisory Notes — Stage 1: Managed Identity

- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permi
```

### Source
Build advisory review

### Required Knowledge File Sections
The new knowledge file MUST include ALL of these sections:
1. **Description** (one-line summary)
2. **When to Use** (scenarios and selection criteria)
3. **POC Defaults** (default SKU, tier, configuration)
4. **Terraform Patterns** (azapi_resource with RBAC)
5. **Bicep Patterns** (ARM template resources)
6. **Application Code** (Python, C#, Node.js — where applicable)
7. **Common Pitfalls** (deployment failures, misconfigurations)
8. **Production Backlog Items** (what changes for production)

Contributor guide

No contributing guide indexed for this repository

Research direction

Create knowledge/services/container-app-api.md and use the issue's eight required sections as the outline. Start by reviewing the Build advisory review content and the requested Terraform, Bicep, and application-code coverage. Done means the new file includes Description, usage guidance, POC defaults, implementation patterns, pitfalls, and production backlog items.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, python, terraform
Domain
cloud, documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.