Azure / Azure/azure-cli

Support Managed Identity for Image ACR pulling in App Service image update command

Open
#28,858 3 comments 0 reactions 2 assignees Claimed by @madsd View on GitHub
act-observability-squad app-service-general Auto-Assign customer-reported Service Attention Web Apps
Dominant language
Python
Stars
4.6k
Forks
3.5k
Avg merge
3d 2h
Merged PRs (30d)
60

Description

**Related command**

az webapp config container set -g my-resource_group -n my-web-app -c my-acr.azurecr.io/myimage:1.0.0 -r https://my-acr.azurecr.io

**Is your feature request related to a problem? Please describe.**

Current implementation only supports ACR username and password which is not the safest approach.
See method 'update_container_settings' at line 2195 https://github.com/Azure/azure-cli/blob/dev/src/azure-cli/azure/cli/command_modules/appservice/custom.py

There is no provisioning for authentication to ACR using managed identity.
This is especially annoying considering the fact that Managed Identity is supported in general for App Service ACR pull.

**Describe the solution you'd like**

'az webapp config container set ' command to use Managed Identity for ACR authentication

**Describe alternatives you've considered**

I cannot find alternative of the image update without getting back to infra deployment, e.g. Terraform infra supplying the image details. I need more robust way of image update.

**Additional context**

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.