azure.datafactory.devops icon indicating copy to clipboard operation
azure.datafactory.devops copied to clipboard

Authentication via WorkloadIdentityFederation

Open aj4314 opened this issue 2 years ago • 5 comments

Hi Kamil,

I recently implemented the publish tool for a CICD pipeline running in Azure Devops and it was very smooth. Thanks for your hard work!

I have a quick question in regards to authentication methods when implementing through Azure Devops. Currently it seems that only the service principle approach or managed service identity works - I tried setting up a service connection using Workload Identity federation and encountered this error: image (6)

Since Azure is now recommending workload identity federation are there any plans to make different authentication approaches viable? My company is trying to move away from managing service principles and having to recycle secrets.

Kind regards!

aj4314 avatar Nov 02 '23 01:11 aj4314

Error message (for searchability): ##[error]Unsupported authentication scheme 'WorkloadIdentityFederation' for Azure endpoint.

NowinskiK avatar Nov 29 '23 19:11 NowinskiK

MSFT fixed recently similar issue here (reference): https://github.com/microsoft/azure-pipelines-tasks/issues/18992 PR details: https://github.com/microsoft/azure-pipelines-tasks/pull/19256/commits/50e3e31ca81204c3bb51a2be9cc050a7d13472cc#diff-e7717abe1d4a4bc136d4e37c1e2695fc81b89047c49dfd7adf9b155d9135a2b9

NowinskiK avatar Nov 29 '23 20:11 NowinskiK

Hi @NowinskiK, any progress on this? We're having the same issue.

timSchw avatar Feb 20 '24 07:02 timSchw

I started working on this, but I don't have a solution yet.

NowinskiK avatar Feb 22 '24 08:02 NowinskiK

Hi, we are experiencing the same issue. We would love to use the recommended authentication method for it - as a workaround we reverted to a SP auth.

ursu123 avatar Apr 09 '24 09:04 ursu123

I have clients who would like to use workload identity federation with the Release pipeline task. Is there an ETA on this yet? I tried it today and am still getting the same error as in this thread.

mlongoria avatar Jun 04 '24 16:06 mlongoria

I hope very soonish...

NowinskiK avatar Jun 06 '24 23:06 NowinskiK

Good news: I finally overcame all obstacles and errors related to the development of this feature. Currently, it's in tests. If you want to have access to Private Preview let me know. It should be deployed in a few days.

NowinskiK avatar Jun 11 '24 22:06 NowinskiK

Released in v.1.34

NowinskiK avatar Jun 12 '24 09:06 NowinskiK

This feature has been reverted from ver.1.x and released in a new major version 2.0, due to backwards incompatibility of related Az.* modules. (Issue #164)

NowinskiK avatar Jun 15 '24 11:06 NowinskiK