When will the Azure Storage FUSE driver (Blobfuse2) support MS Entra Workload Id for mounting to AKS?

Andrej 6 Reputation points
2024-09-27T22:31:23.02+00:00

This GitHub issue details the issue many customers are experiencing attempting to mount Azure Blob Storage to AKS Pods, using Managed Identity (MS Entra Workload Id) and the Azure Storage FUSE driver (Blobfuse2): https://github.com/Azure/AKS/issues/3432#issuecomment-2377117830

Existing documentation is confusing for customers and does not mention the current issues as limitations nor when they will be resolved. For example mounting is NOT supported using Managed Identity, instead the underlying implementation requires elevated Azure Blob Storage privileges (Contributor Role), which many highly regulated customers see as increasing the security risk posture.

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
2,927 questions
Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
2,155 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,155 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Sumarigo-MSFT 47,101 Reputation points Microsoft Employee
    2024-11-07T05:26:41.1033333+00:00

    @Andrej I appreciate the time and patience. Thank you. We have made the changes, please refer to the below link:

    https://github.com/Azure/AKS/issues/3432#issuecomment-2430629778


    Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.