Skip to content

[Knowledge] log-analytics: ## Advisory Notes — Stage 1: Managed Identity - **[Architec... #54

@artspe

Description

@artspe

Knowledge Contribution

Type: Pitfall
File: knowledge/services/log-analytics.md

Context

Advisory Notes — Stage 1: Managed Identity

  • [Architectural Trade-off] A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.

  • [Security] No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev

Rationale

Advisory Notes — Stage 1: Managed Identity

  • [Architectural Trade-off] A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permissions are over-scoped in later stages, every service inherits that exposure. Consider per-service identities for production least-privilege isolation.

  • [Security] No resource lock is applied to the managed identity. Accidental deletion would orphan all downstream RBAC assignments and break ev

Content to Add

## Advisory Notes — Stage 1: Managed Identity

- **[Architectural Trade-off]** A single shared identity across all Container Apps simplifies wiring but increases blast radius — if the identity's permi

Source

Build advisory review

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions