Skip to content

Contracts, endpoints, and configuration ​

Provider contract ​

ProviderDescriptor contains a ProviderSeam, provider ID, adapter version, options-schema version, hosting pattern, and advertised capabilities.

ProviderRegistration adds the enabled state, options revision, and selected schema version. A PinnedProviderBinding records the run, resource generation, and negotiated capabilities.

These records contain no credentials or option values. See providers and models for resolver limits.

Identity broker endpoints ​

These routes belong to the unpublished Identity broker candidate. They are service contracts in source, not deployed product endpoints.

Method and pathContract
GET /connect/authorizeOpenIddict authorization request and external sign-in or consent prompt.
GET /connect/authorize/resumeAuthenticated, single-use external sign-in continuation.
POST /connect/consentConsent handle, approval, optional scope subset, local cookie, and X-CSRF-TOKEN.
POST /connect/tokenForm-encoded authorization-code or refresh exchange.
GET /diagnostics/whoamiBearer validation diagnostic. It is not an audience acceptance test.
POST /secrets/redeemValidated bearer and exact secret ID, version, purpose, and run ID.
GET /health/liveProcess liveness.
GET /health/readyPostgreSQL connectivity.

The service has no grant-administration HTTP endpoint. The browser consent UI is not implemented.

Identity host configuration ​

KeyRequirement
ConnectionStrings:IdentityBrokerIdentity-owned PostgreSQL database for runtime access. Use the separately bootstrapped Entra runtime role and omit a password; ordinary startup verifies but does not migrate.
IdentityBroker:IssuerAbsolute HTTPS issuer.
IdentityBroker:Signing:PfxPathMounted signing, encryption, and data-protection certificate.
IdentityBroker:Signing:PfxPasswordDeployment secret. Do not store it in source control.
IdentityBroker:DataProtectionKeyPathDurable writable key-ring path shared by broker replicas.
IdentityBroker:ExternalProvider:AuthorityAbsolute HTTPS OIDC authority.
IdentityBroker:ExternalProvider:ClientId and ClientSecretRegistered upstream confidential client.
IdentityBroker:ClientsRegistered client IDs, types, redirect URIs, scopes, resources, and secrets.
IdentityBroker:SecretRedemption:AudienceRequired HTTPS audience registered as a client resource.
IdentityBroker:SecretRedemption:VaultUriAzure Key Vault root URI.
IdentityBroker:SecretRedemption:WorkloadIdentityTenantIdExplicit Entra tenant ID.
IdentityBroker:SecretRedemption:WorkloadIdentityClientIdExplicit Entra client ID.
IdentityBroker:SecretRedemption:WorkloadIdentityTokenFilePathAbsolute projected token-file path.

The host does not use ambient credentials or a development-certificate fallback.

Identity PostgreSQL access ​

Runtime and schema migration use separate connection strings, projected workload identities, and Entra PostgreSQL roles. Both connections use passwordless async Npgsql token acquisition, VerifyFull, and the scope https://ossrdbms-aad.database.windows.net/.default.

OperationConfigurationPostgreSQL role and boundary
Ordinary runtimeConnectionStrings:IdentityBroker; IdentityBroker:SecretRedemption:WorkloadIdentityTenantId, WorkloadIdentityClientId, and WorkloadIdentityTokenFilePath.The operator-selected runtime Entra role has CONNECT, schema USAGE, DML on current Identity/OpenIddict tables, and SELECT on the migration history. It does not own the schema or apply migrations.
Explicit migrationRun the executable with only --migrate; provide ConnectionStrings:IdentityBrokerMigration and IdentityBroker:Migration:WorkloadIdentityTenantId, WorkloadIdentityClientId, and WorkloadIdentityTokenFilePath.A separate migration Entra role owns identity_broker and applies migrations. Its workload identity receives no Azure resource role.

The database bootstrap and reviewed grant SQL are operator-run steps. The ordinary host checks that the schema exists and no migrations are pending; it fails rather than creating roles or changing the schema.

AKS Application Routing preview ​

appRoutingDnsZoneResourceIds is an optional deployment input. Empty input requests AKS's managed default domain. One to five unique existing public or private DNS zone IDs request custom domains and disable that default. IDs must belong to the exact authorized subscription, cannot name PrivateLink zones, and can use at most one resource group per zone kind.

The appRoutingDomain output has managedDefaultRequested and domainName fields. For an empty zone list, the template returns the exact defaultDomain.domainName from the AKS response. For custom zones, it returns domainName: null. The source does not construct hostnames or configure HTTP routes.

The appRoutingIdentity output is separate from foundationProbeIdentity. It contains the AKS-generated resourceId, clientId, and objectId.

RoleScope
Key Vault Certificate User (db79e9a7-68ee-4b58-9aeb-b90e7c24fcba)The existing Key Vault resource.
DNS Zone Contributor (befefa01-2a29-4197-83a8-272ff33ce314)Each exact configured public DNS zone.
Private DNS Zone Contributor (b12aa53e-6015-4669-85d0-8515ebb3ae7f)Each exact configured private DNS zone.

The AKS source uses the Preview 2026-07-02-preview API, enables the Key Vault CSI provider, and sets secret rotation to 'true' with a '2m' poll interval. These are source definitions. No live role assignment, addon activation, domain, certificate, or route was verified.

Azure operator command ​

The supported tool reads the exact subscription and tenant supplied by the operator. Deployment requires separate approval for its target and cost.

Run a non-mutating summary with node scripts/azure/deploy.mjs and reviewed target arguments. Add --execute only after approval. The checked-in parameter examples contain placeholders.

External acceptance evidence ​

The Foundation Probe Job reports its resource-operation results, but it does not attest to its own pod identity, pulled image, or exit status. The separate read-only consumer observes the completed Job and pod, checks their ownership and workload-identity projection, and verifies that both the Job image and observed pulled image match the expected registry manifest.

The consumer validates the native probe receipt against the admitted source SHA, Git tree, deployment, identity, and target. It then queries Azure Monitor only after Job completion and requires fresh AppDependencies or AppRequests evidence correlated by source SHA, Git tree, nonce, trace, and span. Configuration checks do not substitute for this runtime proof; incomplete or mismatched evidence remains blocked. Local fixtures validate the consumer contract but do not prove a live deployment.