Share via

When will the Azure Storage FUSE driver (Blobfuse2) support MS Entra Workload Id for mounting to AKS?

Andrej 11 Reputation points
2024-09-27T22:31:23.02+00:00

This GitHub issue details the issue many customers are experiencing attempting to mount Azure Blob Storage to AKS Pods, using Managed Identity (MS Entra Workload Id) and the Azure Storage FUSE driver (Blobfuse2): https://github.com/Azure/AKS/issues/3432#issuecomment-2377117830

Existing documentation is confusing for customers and does not mention the current issues as limitations nor when they will be resolved. For example mounting is NOT supported using Managed Identity, instead the underlying implementation requires elevated Azure Blob Storage privileges (Contributor Role), which many highly regulated customers see as increasing the security risk posture.

Azure Blob Storage
Azure Blob Storage

An Azure service that stores unstructured data in the cloud as blobs.

Azure Kubernetes Service
Azure Kubernetes Service

An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

2 answers

Sort by: Most helpful
  1. Andrej 11 Reputation points
    2025-05-04T10:32:03.6+00:00

    For anyone following this thread, hot off the press: workload identity support on static provisioning

    Was this answer helpful?

    0 comments No comments

  2. Sumarigo-MSFT 47,511 Reputation points Microsoft Employee Moderator
    2024-11-07T05:26:41.1033333+00:00

    @Andrej I appreciate the time and patience. Thank you. We have made the changes, please refer to the below link:

    https://github.com/Azure/AKS/issues/3432#issuecomment-2430629778


    Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.