= Azure/CrossTennantIdentity = * Authinticating accross tenants using Manged Instance and AKS Workload federated identities == AKS federated identity == * https://learn.microsoft.com/en-us/azure/aks/workload-identity-cross-tenant * e.g. Tenant A and Tenant B. 1. TENANT A - AKS with OIDC {{{ ## TENANT A - AKS az login --tenant $TENANT_A_ID az account set --subscription $TENANT_A_SUBSCRIPTION_ID # Create an AKS cluster - TENANT_A with oidc-issuer az aks create \ ... \ --name $CLUSTER_NAME_TENANT_A \ --enable-oidc-issuer \ --enable-workload-identity OIDC_ISSUER_URL=$(az aks show --resource-group $RESOURCE_GROUP --name $CLUSTER_NAME_TENANT_A --query "oidcIssuerProfile.issuerUrl" --output tsv) }}} 2. TENANT B - resource and with user-assigned IDENTITY access {{{ ## TENANT B - e.g. SB az login --tenant $TENANT_B_ID # Set environment variable IDENTITY_NAME=${SERVICEBUS_NAME_TENANT_B}-identity # Create a user-assigned managed identity az identity create --resource-group $RESOURCE_GROUP --name $IDENTITY_NAME # Get the user-assigned managed identity principalId PRINCIPAL_ID=$(az identity show --resource-group $RESOURCE_GROUP --name $IDENTITY_NAME --query principalId --output tsv) CLIENT_ID=$(az identity show --resource-group $RESOURCE_GROUP --name $IDENTITY_NAME --query clientId --output tsv) SERVICEBUS_ID=$(az servicebus namespace show --name $SERVICEBUS_NAME --resource-group $RESOURCE_GROUP --query id --output tsv) az role assignment create \ --role "Azure Service Bus Data Owner" \ --assignee-object-id $PRINCIPAL_ID \ --assignee-principal-type ServicePrincipal \ --scope $SERVICEBUS_ID }}} 3. Establish trust between AKS cluster and managed identity {{{ az identity federated-credential create --name $IDENTITY_NAME-$RANDOM --identity-name $IDENTITY_NAME --resource-group $RESOURCE_GROUP --issuer $OIDC_ISSUER_URL --subject system:serviceaccount:default:myserviceaccount # NOTE: --subject system:serviceaccount:default:myserviceaccount is the name of the Kubernetes service account that you create in Tenant A. # When your application pod makes authentication requests, this value is sent to Microsoft Entra ID as the subject in the authorization request. }}} 4. Now setup the user-assigned identity from Tenant B in Tenant A AKS cluser {{{ kubectl apply -f - <