Repository navigation
az containerapp create not respecting existing user-managed identity and unnecessarily erroring trying to assign permissions #9175
Copy link
Copy link
Open
Labels
Auto-AssignAuto assign by botAuto assign by botContainerAppService AttentionThis issue is responsible by Azure service team.This issue is responsible by Azure service team.bugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.customer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.
Description
Activity
- addedbugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.
on Sep 17, 2025 - addedquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.
on Sep 17, 2025 Thank you for opening this issue, we will look into it.
- addedAuto-AssignAuto assign by botAuto assign by botService AttentionThis issue is responsible by Azure service team.This issue is responsible by Azure service team.
on Sep 17, 2025 microsoft-github-policy-service commented
on Sep 17, 2025 ContributorMore actionsThanks for the feedback! We are routing this to the appropriate team for follow-up. cc Hong Wang (@howang-ms), Greedygre (@Greedygre).
- changed the title
[-]az containerapp create not respecting existing user-managed identity and assigning permissions[/-][+]az containerapp create not respecting existing user-managed identity and unnecessarily erroring trying to assign permissions[/+]on Sep 17, 2025 Obviously, the workaround will be to give the github action's workload identity the permission
Microsoft.Authorization/roleAssignments/writebut that's sub-par from a security perspective.- removedquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
on Sep 17, 2025 Thanks for reporting this issue.
For
az containerapp create --registry-server ${{ ACR registry }}, when run without--registry-identity,--registry-username/--registry-password, it will auto try to use system-identity to pull the image.Log:
Creating an acrpull role assignment for the system identityThen it failed with error:
azure.cli.core.azclierror.UnauthorizedError: Role assignment failed with error message: "(AuthorizationFailed) The client 'guidB' with object id 'guidB' does not have authorization to perform action 'Microsoft.Authorization/roleAssignments/write' over scope '/subscriptions/***/resourceGroups/***/providers/Microsoft.ContainerRegistry/registries/***acr4s45c/providers/Microsoft.Authorization/roleAssignments/e22609a6-f847-4c09-b15c-1134dadbbb00' or the scope is invalid. If access was recently granted, please refresh your credentials.The workaround is run with a valid
--registry-identityor--registry-username/--registry-password.
Metadata
Metadata
Assignees
Labels
Auto-AssignAuto assign by botAuto assign by botContainerAppService AttentionThis issue is responsible by Azure service team.This issue is responsible by Azure service team.bugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.customer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.
Describe the bug
I'm trying to deploy an Azure Functions app to Azure Container Apps using the CLI with the ACA app pulling from ACR using a user managed identity. The create works under my account, but not the GitHub Action OIDC as the credential does not have permissions granting roles.
The docs say (bold for my emphasis)
Giving it a resource ID for user-defined is prompting it to try creating an acrpull role assignment and fail the command entirely because of the lack of permissions but it should be optional to assign permissions.
Related command
az containerapp create
ghaction.yml
Errors
debuglogs.txt
Issue script & Debug output
ghaction.yml
debuglogs.txt
secrets.ACA_USER_ASSIGNED like /subscriptions/<>/resourcegroups/<>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<>
Expected behavior
The create statement should use the user-managed identity and when it cannot assign permissions proceed to attach the user-maanged identity anyway, enabling the script to succeed.
Environment Summary
{
"azure-cli": "2.77.0",
"azure-cli-core": "2.77.0",
"azure-cli-telemetry": "1.1.0",
"extensions": {
"containerapp": "1.2.0b3"
}
}
Additional context
No response
ghaction.yml
debuglogs.txt