Workload Identity (OIDC) for AKS

  Рет қаралды 6,088

Houssem Dellai

Houssem Dellai

Күн бұрын

Scripts: github.com/HoussemDellai/dock...
Follow me on Twitter for more content: / houssemdellai
Chapters:
0:00 - Intro
1:08 - How to connect to Azure resources
3:40 - Existing tools to securely connect to Azure resources
6:09 - How Workload Identity works with AKS
7:26 - Demo
14:17 - Kubernetes Service Account to Azure Managed Identity mapping
15:03 - Resources

Пікірлер: 8
@jakepyrett1715
@jakepyrett1715 6 ай бұрын
Thanks for video. Was excellent
@jamalashraf7957
@jamalashraf7957 Жыл бұрын
I am getting this error --> F1206 09:02:03.164100 1 main.go:15] KEYVAULT_URL environment variable is not set
@SwatiKhandelwal-lu4nt
@SwatiKhandelwal-lu4nt Жыл бұрын
It is asking for many parameter for env which include federated file, how did you not get that value?
@smartaquarius2021
@smartaquarius2021 Жыл бұрын
Enable workload identity feature is in preview and not prod ready yet. Can any share the video to setup same using open source project.
@jamalashraf7957
@jamalashraf7957 Жыл бұрын
Great VIDEO! sir would you please tell me that how can i set these env variables in Azure CLI? I am stuck here
@xville8642
@xville8642 5 ай бұрын
can you give the managed identity RBAC roles on the keyvault instead of using Access Policies? ?
@adamsebetich9290
@adamsebetich9290 3 ай бұрын
yes, that is exactly right. RBAC on key vault is a bit less granular than access policies, but i believe azure wants to move towards rbac for all things anyways
@raghur5678
@raghur5678 Жыл бұрын
i have created workload-identity-sa like this apiVersion: v1 kind: ServiceAccount metadata: annotations: azure.workload.identity: XXX-XXXX-XXX-XXXX labels: azure.workload.identity/use: "true" name: workload-identity-sa namespace: backend-services via yaml from kubernetes ,but its not created and after running this. i am deploying pods into Cluster getting error like Azure.Identity.AuthenticationFailedException: ClientAssertionCredential authentication failed: AADSTS70021: No matching federated identity record found for presented assertion.
Access to AKS control plane (public, private, vnet integration)
25:08
Managed Identity for AKS
16:27
Houssem Dellai
Рет қаралды 4,4 М.
3M❤️ #thankyou #shorts
00:16
ウエスP -Mr Uekusa- Wes-P
Рет қаралды 13 МЛН
孩子多的烦恼?#火影忍者 #家庭 #佐助
00:31
火影忍者一家
Рет қаралды 48 МЛН
ОСКАР vs БАДАБУМЧИК БОЙ!  УВЕЗЛИ на СКОРОЙ!
13:45
Бадабумчик
Рет қаралды 3,9 МЛН
Smart Sigma Kid #funny #sigma #comedy
00:25
CRAZY GREAPA
Рет қаралды 16 МЛН
Workload Identity Protection with Azure AD Identity Protection
27:08
John Savill's Technical Training
Рет қаралды 10 М.
OIDC and Workload Identity in Kubernetes - Ashutosh Kumar, Elastic & Anish Ramasekar, Microsoft
35:25
CNCF [Cloud Native Computing Foundation]
Рет қаралды 1,6 М.
Kubernetes networking on Azure
8:45
Project Calico
Рет қаралды 33 М.
AKS Workload Identity - Quick Tutorial
12:17
Azure Kubernetes Service (AKS)
Рет қаралды 1,9 М.
Understanding Azure AD Conditional Access Workload Identities
19:48
John Craddock Identity and Access Training
Рет қаралды 1 М.
Advancements in Kubernetes Workload Identity for Azure
32:55
CNCF [Cloud Native Computing Foundation]
Рет қаралды 2,3 М.
Monitoring AKS using Prometheus and Grafana on Azure
22:03
Houssem Dellai
Рет қаралды 10 М.
Publish Your AKS Services with Azure Private Link and Front Door
14:33
Introducing Microsoft Entra Workload Identities | OD28
15:27
Microsoft Ignite
Рет қаралды 3 М.
ПОКУПКА ТЕЛЕФОНА С АВИТО?🤭
1:00
Корнеич
Рет қаралды 3,7 МЛН
Самый дорогой кабель Apple
0:37
Romancev768
Рет қаралды 313 М.
1$ vs 500$ ВИРТУАЛЬНАЯ РЕАЛЬНОСТЬ !
23:20
GoldenBurst
Рет қаралды 1,6 МЛН
Мой инст: denkiselef. Как забрать телефон через экран.
0:54