Skip to main content

AZURE_WORKLOAD_IDENTITY_LABEL

Constant AZURE_WORKLOAD_IDENTITY_LABEL 

Source
pub const AZURE_WORKLOAD_IDENTITY_LABEL: &str = "azure.workload.identity/use";
Expand description

Pod label opting a mover pod into the azure-workload-identity mutating webhook: pods carrying azure.workload.identity/use: "true" and running as a federated ServiceAccount get AZURE_TENANT_ID/AZURE_CLIENT_ID/ AZURE_FEDERATED_TOKEN_FILE (and the projected token volume) injected — exactly the env kopia’s azure backend binds its credential flags to. Stamped by the operator (and the CLI’s browse sessions) on every mover pod for a repository whose azure backend uses auth.workloadIdentity. Lives here because the operator and kubectl kopiur must agree on it byte-for-byte.