Azure Workload Identity
An Azure workload can use its managed identity to request a short-lived Microsoft Entra access token. Mixlayer verifies that token and exchanges it for a short-lived Mixlayer access token, so the workload does not need a stored Mixlayer API key.
This guide uses a user-assigned managed identity so its lifecycle is independent of any one Azure resource. A system-assigned identity also works.
1. Create the audience application
In the Microsoft Entra admin center, create a single-tenant app registration to represent Mixlayer as the token audience:
- Open App registrations, select New registration, and choose Accounts in this organizational directory only.
- Under Expose an API, add the default Application ID URI:
api://<application-client-id>. - Open Manifest and set
api.requestedAccessTokenVersionto2. - Record the application (client) ID and your Microsoft Entra tenant ID.
The application registration contains no Mixlayer secret. It gives the managed identity a dedicated audience for tokens intended for Mixlayer.
2. Assign a managed identity
Create or select a user-assigned managed identity and attach it to the Azure resource that runs your workload. Record both identifiers:
All code running within an Azure resource can request tokens for identities assigned to that resource. Do not share the resource with workloads that should have different Mixlayer access.
3. Configure the Mixlayer provider
Create an OIDC provider in Workload Identity:
Map the immutable managed-identity object ID and tenant:
Admit only the expected tenant and managed identity:
Replace the placeholders with your tenant ID and the managed identity’s object (principal) ID. Use true as the final authorization rule and grant only the permissions the workload needs.
4. Request an Entra token
From an Azure VM or virtual machine scale set, request a token through the Instance Metadata Service. The resource is the Application ID URI, while the resulting v2 token’s aud claim is the application’s client ID.
Omit client_id when using a system-assigned identity. Other Azure hosting services expose managed identity through service-specific endpoints; use the Azure Identity SDK there to request a token for api://<application-client-id>.
5. Exchange and use the Entra token
Cache the Mixlayer token in memory until shortly before expiry, then request and exchange a new Entra token.
Troubleshooting
- Decode a sample token locally and confirm
veris2.0,issexactly matches the provider, andaudis the audience application’s client ID. - Confirm
oidis the managed identity’s object (principal) ID, not its client ID. - If the VM has multiple user-assigned identities, include the intended identity’s client ID in the metadata request.
- A metadata error about an unknown resource usually means the Application ID URI is incorrect or belongs to another tenant.
- Do not proxy the Instance Metadata Service or log either access token.