Any alternative of AAD Pod identity?

Tanul 1,251 Reputation points
2022-08-23T20:18:26.56+00:00

Team,

Currently we are using AAD pod identity package to interact with azure key vault from kubernetes. Is there any other alternative available?

As discussed here, its releases happened once a month only i.e. in the first week. This package has vulnerabilities which are difficult to manage because our prisma security team is raising concerns.

Would be grateful if you can share some alternatives for the same. Thank you.

Kind Regards,
Tanul

Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
1,853 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,444 questions
0 comments No comments
{count} votes

Accepted answer
  1. Prrudram-MSFT 21,886 Reputation points
    2022-08-24T17:05:30.457+00:00

    Hello @Tanul ,

    Thank you for reaching out to the Microsoft Q&A platform. Happy to answer your question.
    I understand you are looking for an alternative of AAD Pod identity. As far as I know through this announcement, we are planning to replace AAD Pod Identity with open-source project called Azure Workload Identity. Going forward, we will no longer add new features to this project in favor of Azure Workload Identity. However, we will continue patching critical bugs and security vulnerabilities until further notice.

    With this project, developers can use native Kubernetes concepts of service accounts and federation to access Azure AD protected resources, such as Azure and Microsoft Graph, without needing secrets.

    Refer to doc for release cadence.

    Hope this detail helps.

    --please don't forget to upvote and accept as answer if the reply is helpful--

    234594-image.png

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful