| Entra ID → SPIRE | The federated identity credential on the managed identity: SVIDs from issuer
with subject and audience api://AzureADTokenExchange.
Keys come from the issuer's public /keys. |
| Azure Storage → Entra ID | Azure RBAC: the managed identity has Storage Blob Data Reader on one container. |
| kube-apiserver → Entra ID | AuthenticationConfiguration: Entra v2 issuer, audience = the
homelab-kube-apiserver app. roles map to entra:role:<role>, and RBAC binds
entra:role:Cluster.Viewer → view. |
| Key Vault → Entra ID | Azure RBAC only (no access policies): a separate managed identity, federated with
…/sa/kv-reader, has Key Vault Secrets User on one secret, not the vault. |
| SPIRE → the pod | Registration: the pod's namespace and service account decide its SPIFFE ID (ClusterSPIFFEID). |