Service Accounts in Azure are tied to Active Directory Service Principals. You can read more about Service Principals and AD Applications: "Application and service principal objects in Azure Active Directory".
Kubernetes uses a Service Principal to talk to Azure APIs to dynamically manage resources such as User Defined Routes and L4 Load Balancers.
There are several ways to create a Service Principal in Azure Active Directory:
With the Azure CLI
az login az account set --subscription="${SUBSCRIPTION_ID}" az ad sp create-for-rbac --role="Contributor" --scopes="/subscriptions/${SUBSCRIPTION_ID}"
This will output your
, andtenant
. Thename
may be used for theservicePrincipalProfile.servicePrincipalClientId
and thepassword
is used forservicePrincipalProfile.servicePrincipalClientSecret
.Confirm your service principal by opening a new shell and run the following commands substituting in
, andtenant
:az login --service-principal -u NAME -p PASSWORD --tenant TENANT az vm list-sizes --location westus
With the legacy Azure XPlat CLI
Instructions: "Use Azure CLI to create a service principal to access resources"
With PowerShell
Instructions: "Use Azure PowerShell to create a service principal to access resources"
To get you started quickly, the following are simplified instructions for creating a single-tenant AD application and a service principal with password authentication. Please read the full instructions above for proper RBAC setup of your application. Display name and URI are a friendly arbitrary name and address for your application.
PS> Login-AzureRmAccount -SubscriptionId $subscriptionId PS> $app = New-AzureRmADApplication -DisplayName $name -IdentifierUris $uri -Password $passwd PS> New-AzureRmADServicePrincipal -ApplicationId $app.ApplicationId PS> New-AzureRmRoleAssignment -RoleDefinitionName Contributor -ServicePrincipalName $app.ApplicationId
The first command outputs your
, used below. The$app.ApplicationId
is used for theservicePrincipalProfile.servicePrincipalClientId
and the$passwd
is used forservicePrincipalProfile.servicePrincipalClientSecret
.Confirm your service principal by opening a new PowerShell session and running the following commands. Enter
for username.PS> $creds = Get-Credential PS> Login-AzureRmAccount -ServicePrincipal -TenantId $tenantId -Credential $creds PS> Get-AzureRmVMSize -Location westus
With the Portal
Instructions: "Use portal to create Active Directory application and service principal that can access resources"