ARM template deployment scripts Azure login

Viewed 177

I'm trying to use a Microsoft.Resources/deploymentScripts in my ARM template that will execute some Azure Powershell commands.

Obviously, without specifying any identity attribute, I need to run Connect-AzAccounts in my script.

My question is, how can I retrieve the Service Principal credentials and pass this to my ARM DeploymentScripts?

1 Answers

I'm assuming that the identity you're using to deploy your ARM (the "Deployment Principal") is the same as the one running your Deployment Script (the "Deployment Script Principal"). See this link.

Here's what I did. I specify the "Deployment Service Principal" credentials as ARM parameters, and then pass these to the Deployment Script as secure environment variables (I, too, am using one Principal for both the ARM and the Deployment Script).

This does mean that my ARM Deployment pipeline looks more or less like this:

az login --service-principal -u ${appId} -p ${clientSecret} ...
az deployment group create ... --parameters appId=${appId} clientSecret=${clientSecret}

In other words: I'm specifying the Service Principal Credentials twice:

  1. to login using the Deployment Principal
  2. to pass the Deployment Principal credentials to the Deployment Script

Assuming az login doesn't cache your Service Principal Credentials (let's hope it doesn't!), there is no way to 'fetch' those credentials dynamically, I think.

Related