Skip to content

feat(auth): add Azure AKS/ACR integrations mirroring EKS/ECR - #2790

Merged
Andriy Knysh (aknysh) merged 32 commits into
mainfrom
osterman/aks-acr-support
Aug 13, 2026
Merged

Andriy Knysh (aknysh) merged 32 commits into
mainfrom
osterman/aks-acr-support

Conversation

@osterman

@osterman Erik Osterman (Cloud Posse) (osterman) commented Jul 23, 2026 •

Copy link
Copy Markdown
Member

what

  • Adds atmos azure aks token, atmos azure aks update-kubeconfig, and atmos azure acr login, mirroring the existing atmos aws eks/atmos aws ecr integrations.
  • Generalizes pkg/auth/cloud/kube.KubeconfigManager from AWS-specific to a cloud-agnostic writer shared by EKS and AKS, with a regression suite locking in byte-identical AWS output.
  • Widens the existing IntegrationSpec.Cluster/.Registry schema structs (renamed from EKSCluster/ECRRegistry to Cluster/Registry) so spec.cluster/spec.registry are reused verbatim across aws/eks+azure/aks and aws/ecr+azure/acr — no new per-cloud config keys.
  • Adds AKS-scoped AAD token acquisition to all three Azure identity providers (device-code, OIDC, Azure CLI), alongside their existing Graph/KeyVault token acquisition, since Azure AAD tokens are scope-bound at issuance (unlike AWS SigV4).
  • Adds docs (website/docs/cli/commands/azure/), a changelog post, a roadmap update, two new agent skills (atmos-azure-aks, atmos-azure-acr), and a PRD documenting the design (docs/prd/azure-aks-acr-integrations.md).
  • Remediates 4 open Dependabot alerts found on push: google.golang.org/grpc (xDS RBAC auth bypass / HTTP2 rapid-reset bypass), and three transitive website npm packages (fast-uri, svgo, dompurify).

why

  • Atmos already lets an AWS identity configure kubectl and Docker credentials in one step via atmos auth login. Azure had the same auth foundation (providers, identities) but no equivalent for AKS/ACR, so Azure users still needed the az CLI — and for AAD-enabled clusters, the separate kubelogin binary — outside of Atmos entirely.
  • This closes that gap using the same integration pattern, with no new external tool dependency: AKS cluster description parses the exec-format kubeconfig Azure returns and points the exec plugin at atmos azure aks token instead of kubelogin; ACR login is a plain OAuth2 token exchange, matching what az acr login does under the hood.

references

  • Design: docs/prd/azure-aks-acr-integrations.md
  • Precedent: EKS kubeconfig PRD (docs/prd/eks-kubeconfig.md), ECR authentication PRD (docs/prd/ecr-authentication.md)

manual testing

Exercised end-to-end against a live AAD-enabled AKS cluster (Azure CNI Overlay + Cilium, AAD + Azure RBAC, local accounts disabled) — the live path that PRD Success Metric #2 had previously left to unit tests only. This surfaced, and fixed, a registration gap.

Bug found + fixed. atmos azure aks update-kubeconfig --integration <name> failed with unknown integration kind: azure/aks. The pkg/auth/integrations/azure package self-registers azure/aks and azure/acr in its init(), but nothing blank-imported that package in pkg/auth/manager.go (unlike the aws and github integration packages), so init() never ran and the kinds never registered. The unit suites import the azure package directly, which registered the kinds incidentally and masked the missing production import. Fixed by adding the blank import alongside aws/github.

Integration mode — describe the cluster and write kubeconfig via the Go SDK (no az, no kubelogin):

$ atmos azure aks update-kubeconfig --integration dev/aks
✓ AKS kubeconfig: dev-aks → ~/.config/atmos/kube/config

$ export KUBECONFIG=~/.config/atmos/kube/config
$ kubectl config current-context
dev-aks

$ kubectl get pods -A
NAMESPACE     NAME                              READY   STATUS    RESTARTS   AGE
kube-system   cilium-8trqv                      3/3     Running   0          134m
kube-system   coredns-5d474ff6db-pknhn          1/1     Running   0          132m
kube-system   metrics-server-5b879b45fc-5nxzs   2/2     Running   0          129m
...

The kubeconfig Atmos wrote drives its exec plugin through atmos azure aks token (not kubelogin), with --server-id discovered from the cluster (here the well-known AKS AAD server app):

$ kubectl config view --raw -o jsonpath='{.users[0].user.exec.command} {.users[0].user.exec.args}'
atmos [azure aks token --cluster-name aks-dev --resource-group rg-aks-cus \
       --server-id 6dae42f8-4368-4678-94ff-3960e28e3630 --subscription-id <redacted> --identity=dev]

auth exec mode — Atmos injects KUBECONFIG into the child process from the integration's Environment() (works even with auto_provision: false, which only suppresses the auto-write on login, not the env composition), so no manual export is needed:

$ atmos auth exec --identity dev -- kubectl get nodes
NAME                             STATUS   ROLES    AGE    VERSION
aks-system-64934532-vmss000000   Ready    <none>   139m   v1.35.6
aks-system-64934532-vmss000001   Ready    <none>   139m   v1.35.6

Both paths mint bearer tokens through atmos azure aks token against the Atmos-managed identity — no az CLI and no kubelogin binary. (ACR login against a live registry remains unit-test-only.)

Extends the `auth.integrations` system to Azure: `atmos azure aks token`,
`atmos azure aks update-kubeconfig`, and `atmos azure acr login`, so
`atmos auth login` can provision kubectl and Docker credentials for
Azure the same way it already does for AWS EKS/ECR — no `az` CLI or
`kubelogin` binary required.

Generalizes `pkg/auth/cloud/kube.KubeconfigManager` from AWS-specific to
a cloud-agnostic writer shared by both clouds, and widens the existing
`Cluster`/`Registry` schema structs (renamed from `EKSCluster`/`ECRRegistry`)
so `spec.cluster`/`spec.registry` are reused verbatim across
`aws/eks`+`azure/aks` and `aws/ecr`+`azure/acr`. Since Azure AAD tokens
are scope-bound at issuance (unlike AWS SigV4), all three Azure identity
providers now acquire an AKS-scoped token at login time alongside their
existing Graph/KeyVault tokens.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bumps four vulnerable dependencies to their patched versions, all
within the semver-major bump policy allowed by .github/dependabot.yml:

- google.golang.org/grpc v1.81.1 -> v1.82.1 (GHSA-hrxh-6v49-42gf):
  xDS RBAC authorization fail-open, HTTP/2 Rapid Reset mitigation
  bypass, and an RBAC-engine panic.
- fast-uri (website, transitive) -> 3.1.4 (GHSA-v2hh-gcrm-f6hx): host
  confusion via literal backslash authority delimiter.
- svgo (website, transitive) -> 3.3.4 (GHSA-2p49-hgcm-8545):
  removeScripts plugin left some executable scripts intact.
- dompurify (website, transitive) -> 3.4.12 (GHSA-c2j3-45gr-mqc4):
  CUSTOM_ELEMENT_HANDLING bypassed afterSanitizeElements for allowed
  custom elements.

Regenerated NOTICE via scripts/generate-notice.sh. No CodeQL alerts
were open at remediation time.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@atmos-pro

atmos-pro Bot commented Jul 23, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@osterman Erik Osterman (Cloud Posse) (osterman) added the minor New features that do not break anything label Jul 23, 2026
@github-actions github-actions Bot added the size/xl Extra large size PR label Jul 23, 2026
@github-actions

github-actions Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

go.mod

PackageVersionLicenseIssue Type
github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/containerservice/armcontainerservice/v66.6.0NullUnknown License
Allowed Licenses: MIT, MIT-0, Apache-2.0, BSD-2-Clause, BSD-2-Clause-Views, BSD-3-Clause, ISC, MPL-2.0, 0BSD, Unlicense, CC0-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, Python-2.0, OFL-1.1, LicenseRef-scancode-generic-cla, LicenseRef-scancode-unknown-license-reference, LicenseRef-scancode-unicode, LicenseRef-scancode-google-patent-license-golang
Excluded from license check: pkg:golang/github.com/antlr4-go/antlr/v4, pkg:golang/github.com/google/cel-go, pkg:golang/golang.org/x/image, pkg:golang/modernc.org/libc, pkg:golang/github.com/opencontainers/go-digest, pkg:npm/pako, pkg:npm/sax

Scanned Files

  • go.mod

Condenses the ECR/ACR and EKS/AKS integration sections into one
combined section so the file stays under agent-skills' 500-line limit.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jul 23, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: a53ee53f-d116-438f-a4d1-90d206cae330

📥 Commits

Reviewing files that changed from the base of the PR and between 081071d and acdff40.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (2)
  • NOTICE
  • go.mod
🚧 Files skipped from review as they are similar to previous changes (2)
  • NOTICE
  • go.mod

📝 Walkthrough

Walkthrough

Adds native Azure authentication for AKS and ACR. The change introduces shared AWS/Azure schemas, Azure providers and integrations, CLI commands, AKS token and kubeconfig flows, ACR Docker authentication, registration wiring, tests, documentation, and the Azure SDK dependency.

Changes

Azure authentication and CLI flows

Layer / File(s) Summary
Shared contracts and cloud adapters
pkg/auth/cloud/azure/..., pkg/auth/cloud/kube/..., pkg/auth/types/..., pkg/schema/..., pkg/datafetcher/schema/...
Adds Azure credential fields, AKS and ACR authentication helpers, shared Cluster and Registry schemas, and cloud-agnostic kubeconfig generation.
Azure providers and integrations
pkg/auth/providers/azure/..., pkg/auth/integrations/azure/..., pkg/auth/integrations/types.go, pkg/auth/manager.go
Adds AKS-scoped token acquisition, Azure AKS and ACR integrations, Docker and kubeconfig environment handling, cleanup, validation, and production registration.
Azure command surface
cmd/azure/..., cmd/root.go
Adds atmos azure, atmos azure acr login, atmos azure aks token, and atmos azure aks update-kubeconfig.
AWS compatibility and validation
pkg/auth/cloud/aws/..., pkg/auth/integrations/aws/..., pkg/auth/cloud/kube/*_test.go
Updates AWS integrations and kubeconfig tests to use shared schema types and ClusterInfo while preserving EKS and ECR behavior.
Documentation and support
website/docs/cli/commands/azure/..., website/blog/..., agent-skills/..., docs/prd/...
Documents Azure commands, integrations, configuration, token flows, kubeconfig behavior, ACR credentials, and live verification.
Dependency and CLI artifacts
go.mod, NOTICE, tests/snapshots/..., website/static/casts/..., demo/casts/...
Adds the Azure Container Service SDK license metadata and updates CLI help, screencast, roadmap, and validation artifacts.

Estimated code review effort: 5 (Critical) | ~120 minutes

Mergeability Score: ⚪ Minimal · up to acdff

The PR adds Azure AKS/ACR authentication integrations and related dependency updates; no actionable merge-blocking risk remains beyond normal checks and review.

Possibly related PRs

Suggested reviewers: aknysh

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 22.43% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main change: adding Azure AKS and ACR integrations modeled on existing AWS integrations.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch osterman/aks-acr-support

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

Resource Changes Found for bucket in test

Atmos CI

create

Plan: 4 to add, 0 to change, 0 to destroy.
To reproduce this locally, run:

atmos terraform plan bucket -s test

Create

+ aws_s3_bucket.checkov_target
+ aws_s3_bucket.this
+ aws_s3_bucket.trivy_target
+ aws_s3_bucket_public_access_block.trivy_target
Terraform Plan Summary
  # aws_s3_bucket.checkov_target will be created
  + resource "aws_s3_bucket" "checkov_target" {
      + acceleration_status         = (known after apply)
      + acl                         = (known after apply)
      + arn                         = (known after apply)
      + bucket                      = "atmos-native-ci-e2e-checkov-test"
      + bucket_domain_name          = (known after apply)
      + bucket_prefix               = (known after apply)
      + bucket_regional_domain_name = (known after apply)
      + force_destroy               = false
      + hosted_zone_id              = (known after apply)
      + id                          = (known after apply)
      + object_lock_enabled         = (known after apply)
      + policy                      = (known after apply)
      + region                      = (known after apply)
      + request_payer               = (known after apply)
      + tags_all                    = (known after apply)
      + website_domain              = (known after apply)
      + website_endpoint            = (known after apply)

      + cors_rule (known after apply)

      + grant (known after apply)

      + lifecycle_rule (known after apply)

      + logging (known after apply)

      + object_lock_configuration (known after apply)

      + replication_configuration (known after apply)

      + server_side_encryption_configuration (known after apply)

      + versioning (known after apply)

      + website (known after apply)
    }

  # aws_s3_bucket.this will be created
  + resource "aws_s3_bucket" "this" {
      + acceleration_status         = (known after apply)
      + acl                         = (known after apply)
      + arn                         = (known after apply)
      + bucket                      = "atmos-native-ci-e2e-test"
      + bucket_domain_name          = (known after apply)
      + bucket_prefix               = (known after apply)
      + bucket_regional_domain_name = (known after apply)
      + force_destroy               = false
      + hosted_zone_id              = (known after apply)
      + id                          = (known after apply)
      + object_lock_enabled         = (known after apply)
      + policy                      = (known after apply)
      + region                      = (known after apply)
      + request_payer               = (known after apply)
      + tags                        = {
          + "AtmosFixture" = "native-ci-e2e"
          + "Stage"        = "test"
        }
      + tags_all                    = {
          + "AtmosFixture" = "native-ci-e2e"
          + "Stage"        = "test"
        }
      + website_domain              = (known after apply)
      + website_endpoint            = (known after apply)

      + cors_rule (known after apply)

      + grant (known after apply)

      + lifecycle_rule (known after apply)

      + logging (known after apply)

      + object_lock_configuration (known after apply)

      + replication_configuration (known after apply)

      + server_side_encryption_configuration (known after apply)

      + versioning (known after apply)

      + website (known after apply)
    }

  # aws_s3_bucket.trivy_target will be created
  + resource "aws_s3_bucket" "trivy_target" {
      + acceleration_status         = (known after apply)
      + acl                         = (known after apply)
      + arn                         = (known after apply)
      + bucket                      = "atmos-native-ci-e2e-trivy-test"
      + bucket_domain_name          = (known after apply)
      + bucket_prefix               = (known after apply)
      + bucket_regional_domain_name = (known after apply)
      + force_destroy               = false
      + hosted_zone_id              = (known after apply)
      + id                          = (known after apply)
      + object_lock_enabled         = (known after apply)
      + policy                      = (known after apply)
      + region                      = (known after apply)
      + request_payer               = (known after apply)
      + tags_all                    = (known after apply)
      + website_domain              = (known after apply)
      + website_endpoint            = (known after apply)

      + cors_rule (known after apply)

      + grant (known after apply)

      + lifecycle_rule (known after apply)

      + logging (known after apply)

      + object_lock_configuration (known after apply)

      + replication_configuration (known after apply)

      + server_side_encryption_configuration (known after apply)

      + versioning (known after apply)

      + website (known after apply)
    }

  # aws_s3_bucket_public_access_block.trivy_target will be created
  + resource "aws_s3_bucket_public_access_block" "trivy_target" {
      + block_public_acls       = true
      + block_public_policy     = true
      + bucket                  = (known after apply)
      + id                      = (known after apply)
      + ignore_public_acls      = true
      + restrict_public_buckets = true
    }

Plan: 4 to add, 0 to change, 0 to destroy.

Changes to Outputs:
  + bucket_name = "atmos-native-ci-e2e-test"

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
pkg/auth/cloud/kube/config.go (2)

232-251: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Correct the generalized ID contract.

ListClusterIDs now returns AWS ARNs or Azure ARM resource IDs, but its exported comment and local variable still call every value an ARN.

Suggested fix
-// ListClusterIDs returns all cluster ARN keys from the kubeconfig file.
+// ListClusterIDs returns all cluster ID keys from the kubeconfig file.
 ...
-	arns := make([]string, 0, len(existing.Clusters))
+	ids := make([]string, 0, len(existing.Clusters))
 	for k := range existing.Clusters {
-		arns = append(arns, k)
+		ids = append(ids, k)
 	}
 
-	return arns, nil
+	return ids, nil
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/auth/cloud/kube/config.go` around lines 232 - 251, Update the exported
comment for KubeconfigManager.ListClusterIDs and rename the local arns variable
to a provider-neutral name, such as clusterIDs, so the method clearly represents
both AWS ARNs and Azure ARM resource IDs without changing behavior.

266-298: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Prevent AKS auth-info collisions across subscriptions.

Azure passes the resource group as Region, but resource groups are unique only within a subscription. Two AKS clusters with the same name and resource group in different subscriptions therefore get separate cluster/context entries but the same AuthInfo key; merging the second can overwrite the exec configuration used by the first. "error" mode also misses this collision.

  • pkg/auth/cloud/kube/config.go#L266-L298: carry a caller-provided unique auth-info name (or a subscription/resource-ID suffix), preserve the AWS legacy name, and reject an existing AuthInfo collision in "error" mode.
  • docs/prd/azure-aks-acr-integrations.md#L165-L169: remove the claim that resource group alone provides username uniqueness and document the subscription dimension.

Add a regression test for two same-name/same-resource-group AKS clusters in different subscriptions.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/auth/cloud/kube/config.go` around lines 266 - 298, The kubeconfig
construction around userName and config.AuthInfos must use a caller-provided
unique auth-info name or subscription/resource-ID suffix for Azure, while
preserving the existing AWS legacy naming; in “error” mode, reject an
already-existing AuthInfo collision instead of overwriting it. Update
docs/prd/azure-aks-acr-integrations.md lines 165-169 to remove
resource-group-only uniqueness and document the subscription dimension. Add a
regression test covering same-name, same-resource-group AKS clusters from
different subscriptions.
🧹 Nitpick comments (2)
cmd/azure/aks/token.go (1)

239-245: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Use flags.NewStandardParser() for token command flags.

tokenCmd's flags are registered directly on the pflag.FlagSet instead of going through flags.NewStandardParser(), unlike the sibling update_kubeconfig.go in the same package. As per coding guidelines, "CLI commands must use flags.NewStandardParser() for command-specific flags and must not call viper.BindEnv() or viper.BindPFlag() directly."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmd/azure/aks/token.go` around lines 239 - 245, Update init and the tokenCmd
flag registration to use flags.NewStandardParser() for the command-specific
flags, matching the sibling update_kubeconfig implementation. Register
cluster-name, resource-group, subscription-id, and identity through the standard
parser rather than directly on tokenCmd.Flags(), while preserving their names,
defaults, descriptions, and shorthand.

Source: Coding guidelines

pkg/auth/providers/azure/cli.go (1)

154-165: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Sequential second az call doubles CLI-provider auth latency for everyone.

The AKS-scoped token fetch spawns a second az process serially after the primary token fetch, on every Authenticate() call — even for identities that never touch AKS. Since it's best-effort and independent of the primary token, consider running it concurrently (goroutine/errgroup) so non-AKS users don't pay the extra az process latency.

⚡ Sketch: run the AKS-scoped fetch concurrently
-	// Acquire an AKS-scoped token, for `atmos azure aks token` (best-effort,
-	// non-fatal — az CLI-backed identities without AKS access simply won't
-	// have an AKSToken populated).
-	if aksResp, err := p.executeAzCommand(ctx, azureCloud.AKSServerAppID); err != nil {
-		log.Debug("Failed to acquire AKS token via az CLI, atmos azure aks token may not work", "error", err)
-	} else if aksExpiresOn, err := parseAzureCLITime(aksResp.ExpiresOn); err != nil {
-		log.Debug("Failed to parse AKS token expiration via az CLI, atmos azure aks token may not work", "error", err)
-	} else {
-		creds.AKSToken = aksResp.AccessToken
-		creds.AKSTokenExpiration = aksExpiresOn.Format(time.RFC3339)
-		log.Debug("Acquired AKS token via az CLI", "expiresOn", creds.AKSTokenExpiration)
-	}
+	// Acquire an AKS-scoped token concurrently with the rest of Authenticate's
+	// bookkeeping, for `atmos azure aks token` (best-effort, non-fatal).
+	aksDone := make(chan struct{})
+	go func() {
+		defer close(aksDone)
+		if aksResp, err := p.executeAzCommand(ctx, azureCloud.AKSServerAppID); err != nil {
+			log.Debug("Failed to acquire AKS token via az CLI, atmos azure aks token may not work", "error", err)
+		} else if aksExpiresOn, err := parseAzureCLITime(aksResp.ExpiresOn); err != nil {
+			log.Debug("Failed to parse AKS token expiration via az CLI, atmos azure aks token may not work", "error", err)
+		} else {
+			creds.AKSToken = aksResp.AccessToken
+			creds.AKSTokenExpiration = aksExpiresOn.Format(time.RFC3339)
+			log.Debug("Acquired AKS token via az CLI", "expiresOn", creds.AKSTokenExpiration)
+		}
+	}()
+	<-aksDone // wait here, or move the wait past unrelated bookkeeping to overlap work
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/auth/providers/azure/cli.go` around lines 154 - 165, Update the
Authenticate flow around the primary token fetch and AKS token block to run the
AKS-scoped executeAzCommand call concurrently rather than serially after the
primary request. Preserve its best-effort behavior, existing parseAzureCLITime
handling, credential population, and debug logs, and ensure Authenticate waits
for the concurrent work before returning any resulting credentials.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmd/azure/acr/login.go`:
- Around line 208-223: Replace the direct identity and registry flag
registrations in init with the command-local standard parser via
flags.NewStandardParser. Preserve the existing flag names, shorthands, defaults,
descriptions, and optional --identity behavior using the parser’s NoOptDefVal
support, then attach the parser to loginCmd before adding it to AcrCmd.
- Around line 77-91: Update the explicit-registry branch in the login command
before calling executeExplicitRegistries to reject any supplied identityName or
integrationName, preserving the mutual-exclusivity error behavior used by
executeWithAuthManager. Only execute explicit registry login when neither
auth-manager argument is provided.

In `@pkg/auth/cloud/azure/aks.go`:
- Around line 92-117: Update the AKS authentication flow so the ServerID parsed
by DescribeCluster and stored in AKSClusterInfo is propagated by
BuildKubeClusterInfo to GetToken. Have GetToken request or refresh the token
using info.ServerID/.default instead of the credential-scoped AKSServerScope,
ensuring kubectl receives a cluster-scoped audience for custom or legacy AKS
server app IDs.

In `@pkg/auth/integrations/azure/aks.go`:
- Around line 278-296: findClusterID currently matches AKS resource IDs by
cluster name alone; include a.cluster.ResourceGroup in the full Azure
managed-cluster suffix so Cleanup selects the correct kubeconfig entry. In
pkg/auth/integrations/azure/aks.go lines 278-296, update findClusterID’s
matching suffix; in pkg/auth/integrations/azure/aks_test.go lines 476-504, add
coverage with same-named clusters in different resource groups and assert the
configured resource group’s ID is returned.

In `@website/docs/cli/commands/azure/acr-login.mdx`:
- Around line 9-13: Add the required static CastPlayer terminal demonstration
after the Intro in each affected Azure documentation page:
website/docs/cli/commands/azure/acr-login.mdx (ACR login cast),
website/docs/cli/commands/azure/aks/aks.mdx (AKS command-group cast),
website/docs/cli/commands/azure/aks/update-kubeconfig.mdx (kubeconfig workflow
cast), website/docs/cli/commands/azure/azure-aks-token.mdx (exec-credential
token cast), and website/docs/cli/commands/azure/usage.mdx (Azure command-group
cast).

In `@website/docs/cli/commands/azure/aks/update-kubeconfig.mdx`:
- Around line 14-16: Add a “## Usage” heading immediately before the command
synopsis in the AKS update-kubeconfig documentation, preserving the existing
command and surrounding structure.

---

Outside diff comments:
In `@pkg/auth/cloud/kube/config.go`:
- Around line 232-251: Update the exported comment for
KubeconfigManager.ListClusterIDs and rename the local arns variable to a
provider-neutral name, such as clusterIDs, so the method clearly represents both
AWS ARNs and Azure ARM resource IDs without changing behavior.
- Around line 266-298: The kubeconfig construction around userName and
config.AuthInfos must use a caller-provided unique auth-info name or
subscription/resource-ID suffix for Azure, while preserving the existing AWS
legacy naming; in “error” mode, reject an already-existing AuthInfo collision
instead of overwriting it. Update docs/prd/azure-aks-acr-integrations.md lines
165-169 to remove resource-group-only uniqueness and document the subscription
dimension. Add a regression test covering same-name, same-resource-group AKS
clusters from different subscriptions.

---

Nitpick comments:
In `@cmd/azure/aks/token.go`:
- Around line 239-245: Update init and the tokenCmd flag registration to use
flags.NewStandardParser() for the command-specific flags, matching the sibling
update_kubeconfig implementation. Register cluster-name, resource-group,
subscription-id, and identity through the standard parser rather than directly
on tokenCmd.Flags(), while preserving their names, defaults, descriptions, and
shorthand.

In `@pkg/auth/providers/azure/cli.go`:
- Around line 154-165: Update the Authenticate flow around the primary token
fetch and AKS token block to run the AKS-scoped executeAzCommand call
concurrently rather than serially after the primary request. Preserve its
best-effort behavior, existing parseAzureCLITime handling, credential
population, and debug logs, and ensure Authenticate waits for the concurrent
work before returning any resulting credentials.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: f07a89cc-33a3-4c4b-98be-790e315dc071

📥 Commits

Reviewing files that changed from the base of the PR and between 176a655 and c2c8427.

⛔ Files ignored due to path filters (2)
  • go.sum is excluded by !**/*.sum
  • website/pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (66)
  • .claude/skills/atmos-azure-acr
  • .claude/skills/atmos-azure-aks
  • NOTICE
  • agent-skills/skills/atmos-auth/SKILL.md
  • agent-skills/skills/atmos-azure-acr/SKILL.md
  • agent-skills/skills/atmos-azure-aks/SKILL.md
  • cmd/aws/eks/update_kubeconfig_sdk.go
  • cmd/azure/acr/acr.go
  • cmd/azure/acr/login.go
  • cmd/azure/acr/login_test.go
  • cmd/azure/aks/aks.go
  • cmd/azure/aks/token.go
  • cmd/azure/aks/token_test.go
  • cmd/azure/aks/update_kubeconfig.go
  • cmd/azure/aks/update_kubeconfig_sdk.go
  • cmd/azure/aks/update_kubeconfig_test.go
  • cmd/azure/azure.go
  • cmd/root.go
  • docs/prd/azure-aks-acr-integrations.md
  • errors/errors.go
  • go.mod
  • pkg/auth/cloud/aws/eks.go
  • pkg/auth/cloud/aws/eks_test.go
  • pkg/auth/cloud/azure/acr.go
  • pkg/auth/cloud/azure/acr_test.go
  • pkg/auth/cloud/azure/aks.go
  • pkg/auth/cloud/azure/aks_test.go
  • pkg/auth/cloud/azure/config.go
  • pkg/auth/cloud/azure/config_test.go
  • pkg/auth/cloud/azure/constants.go
  • pkg/auth/cloud/azure/mock_aks_client_test.go
  • pkg/auth/cloud/kube/config.go
  • pkg/auth/cloud/kube/config_diff_test.go
  • pkg/auth/cloud/kube/config_test.go
  • pkg/auth/cloud/kube/multi_cluster_test.go
  • pkg/auth/identities/azure/subscription.go
  • pkg/auth/identities/azure/subscription_test.go
  • pkg/auth/integrations/aws/ecr.go
  • pkg/auth/integrations/aws/ecr_public_test.go
  • pkg/auth/integrations/aws/ecr_test.go
  • pkg/auth/integrations/aws/eks.go
  • pkg/auth/integrations/aws/eks_test.go
  • pkg/auth/integrations/azure/acr.go
  • pkg/auth/integrations/azure/acr_test.go
  • pkg/auth/integrations/azure/aks.go
  • pkg/auth/integrations/azure/aks_test.go
  • pkg/auth/integrations/registry_test.go
  • pkg/auth/integrations/types.go
  • pkg/auth/manager_integrations_test.go
  • pkg/auth/providers/azure/cli.go
  • pkg/auth/providers/azure/device_code.go
  • pkg/auth/providers/azure/oidc.go
  • pkg/auth/providers/azure/oidc_test.go
  • pkg/auth/types/azure_credentials.go
  • pkg/datafetcher/schema/atmos/config/1.0.json
  • pkg/schema/schema_auth.go
  • website/blog/2026-07-23-azure-aks-acr-authentication.mdx
  • website/docs/cli/commands/azure/_category_.json
  • website/docs/cli/commands/azure/acr-login.mdx
  • website/docs/cli/commands/azure/aks/_category_.json
  • website/docs/cli/commands/azure/aks/aks.mdx
  • website/docs/cli/commands/azure/aks/update-kubeconfig.mdx
  • website/docs/cli/commands/azure/azure-aks-token.mdx
  • website/docs/cli/commands/azure/usage.mdx
  • website/package.json
  • website/src/data/roadmap.js

Comment thread cmd/azure/acr/login.go
Comment thread cmd/azure/acr/login.go
Comment thread pkg/auth/cloud/azure/aks.go
Comment thread pkg/auth/integrations/azure/aks.go
Comment thread website/docs/cli/commands/azure/acr-login.mdx
Comment thread website/docs/cli/commands/azure/aks/update-kubeconfig.mdx
Numbered-list continuation lines used 3-space indentation instead of a
multiple of 2, and the architecture diagram had a matching off-by-one;
both tripped the repo's editorconfig CI check.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
docs/prd/azure-aks-acr-integrations.md (1)

88-101: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Narrow the token-isolation claim for non-default server applications.

The architecture and security sections imply every AKS token is scoped to the cluster’s server application, but the future-enhancement section says non-default --server-id support is not implemented and currently only warns. Document those clusters as unsupported/fail-closed, or limit the guarantee to the well-known default server application.

Also applies to: 335-337, 353-356

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/prd/azure-aks-acr-integrations.md` around lines 88 - 101, Update the AKS
token-isolation claims in the architecture, security, and referenced
future-enhancement sections to apply only to the well-known default server
application, or explicitly state that non-default --server-id clusters are
unsupported and fail closed. Align the kubectl token flow and all related
guarantees with the existing behavior that only warns for unsupported
non-default server IDs.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@docs/prd/azure-aks-acr-integrations.md`:
- Around line 88-101: Update the AKS token-isolation claims in the architecture,
security, and referenced future-enhancement sections to apply only to the
well-known default server application, or explicitly state that non-default
--server-id clusters are unsupported and fail closed. Align the kubectl token
flow and all related guarantees with the existing behavior that only warns for
unsupported non-default server IDs.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: e2381aa6-ea96-433e-973c-71f8d8e3ee61

📥 Commits

Reviewing files that changed from the base of the PR and between c2c8427 and f656e77.

📒 Files selected for processing (1)
  • docs/prd/azure-aks-acr-integrations.md

The new atmos azure command group added a row to the top-level help
output that the CLI acceptance-test snapshots didn't account for.
@codecov

codecov Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 85.98351% with 119 lines in your changes missing coverage. Please review.
✅ Project coverage is 82.99%. Comparing base (6c44717) to head (21cadd2).

Files with missing lines Patch % Lines
pkg/auth/providers/azure/device_code.go 25.00% 24 Missing and 3 partials ⚠️
pkg/auth/cloud/azure/acr.go 71.05% 20 Missing and 2 partials ⚠️
pkg/auth/integrations/azure/aks.go 88.11% 10 Missing and 7 partials ⚠️
cmd/azure/acr/login.go 86.25% 8 Missing and 3 partials ⚠️
cmd/azure/aks/token.go 90.80% 7 Missing and 1 partial ⚠️
pkg/auth/cloud/azure/aks.go 95.38% 3 Missing and 3 partials ⚠️
pkg/auth/providers/azure/cli.go 66.66% 2 Missing and 3 partials ⚠️
cmd/azure/aks/update_kubeconfig.go 90.24% 2 Missing and 2 partials ⚠️
cmd/azure/aks/update_kubeconfig_sdk.go 92.45% 2 Missing and 2 partials ⚠️
pkg/auth/integrations/azure/acr.go 93.75% 2 Missing and 2 partials ⚠️
... and 5 more
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #2790      +/-   ##
==========================================
+ Coverage   82.98%   82.99%   +0.01%     
==========================================
  Files        1881     1891      +10     
  Lines      183067   183860     +793     
==========================================
+ Hits       151925   152602     +677     
- Misses      23317    23401      +84     
- Partials     7825     7857      +32     
Flag Coverage Δ
unittests 82.99% <85.98%> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
cmd/azure/azure.go 100.00% <100.00%> (ø)
cmd/root.go 78.41% <ø> (ø)
errors/errors.go 100.00% <ø> (ø)
pkg/auth/cloud/aws/eks.go 96.38% <100.00%> (+1.74%) ⬆️
pkg/auth/integrations/aws/ecr.go 93.84% <100.00%> (ø)
pkg/auth/integrations/aws/eks.go 85.18% <100.00%> (ø)
pkg/auth/manager.go 84.26% <ø> (ø)
pkg/auth/types/azure_credentials.go 79.54% <100.00%> (ø)
pkg/schema/schema_auth.go 100.00% <ø> (ø)
cmd/aws/eks/update_kubeconfig_sdk.go 0.00% <0.00%> (ø)
... and 14 more

... and 8 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@pkg/auth/integrations/azure/aks_test.go`:
- Around line 514-521: Update the cluster fixture loop in WriteClusterConfig so
the nonmatching alias uses Region "other-rg" alongside wrongID, while the target
alias retains "target-rg" with wantID. Keep the fixture metadata internally
consistent and preserve the existing disambiguation assertions.

In `@pkg/auth/providers/azure/cli_test.go`:
- Around line 19-32: Replace the shell-based az fixture in
TestCLIProvider_Authenticate_UsesClusterServerID with a platform-independent
Go-native fake, using the existing helper-process fixture or package-level
command hook if available. Preserve the current argument matching and JSON
responses for the custom server ID and management-token paths, while removing
the executable script, shell syntax, and PATH manipulation.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 1d415aa5-a7ed-4438-add6-e2bb22fdfe27

📥 Commits

Reviewing files that changed from the base of the PR and between 664488e and 60b89df.

📒 Files selected for processing (23)
  • cmd/azure/acr/login.go
  • cmd/azure/acr/login_test.go
  • cmd/azure/aks/token.go
  • cmd/azure/aks/token_test.go
  • demo/casts/atmos.d/screengrabs/cli.yaml
  • pkg/auth/cloud/azure/aks.go
  • pkg/auth/cloud/azure/aks_test.go
  • pkg/auth/integrations/azure/aks.go
  • pkg/auth/integrations/azure/aks_test.go
  • pkg/auth/providers/azure/cli.go
  • pkg/auth/providers/azure/cli_test.go
  • pkg/auth/providers/azure/device_code.go
  • pkg/auth/providers/azure/oidc.go
  • website/docs/cli/commands/azure/acr-login.mdx
  • website/docs/cli/commands/azure/aks/aks.mdx
  • website/docs/cli/commands/azure/aks/update-kubeconfig.mdx
  • website/docs/cli/commands/azure/azure-aks-token.mdx
  • website/docs/cli/commands/azure/usage.mdx
  • website/static/casts/screengrabs/atmos-azure--help.cast
  • website/static/casts/screengrabs/atmos-azure-acr-login--help.cast
  • website/static/casts/screengrabs/atmos-azure-aks--help.cast
  • website/static/casts/screengrabs/atmos-azure-aks-token--help.cast
  • website/static/casts/screengrabs/atmos-azure-aks-update-kubeconfig--help.cast
🚧 Files skipped from review as they are similar to previous changes (12)
  • website/docs/cli/commands/azure/usage.mdx
  • website/docs/cli/commands/azure/aks/aks.mdx
  • website/docs/cli/commands/azure/aks/update-kubeconfig.mdx
  • pkg/auth/providers/azure/oidc.go
  • pkg/auth/providers/azure/cli.go
  • pkg/auth/cloud/azure/aks_test.go
  • pkg/auth/integrations/azure/aks.go
  • website/docs/cli/commands/azure/azure-aks-token.mdx
  • cmd/azure/aks/token_test.go
  • cmd/azure/acr/login.go
  • website/docs/cli/commands/azure/acr-login.mdx
  • cmd/azure/aks/token.go

Comment thread pkg/auth/integrations/azure/aks_test.go Outdated
Comment thread pkg/auth/providers/azure/cli_test.go Outdated
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 23, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🧹 Nitpick comments (1)
cmd/azure/aks/update_kubeconfig_sdk_test.go (1)

106-129: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the wrapped error cause.

The table accepts any error for configuration, manager, and authentication failures. Set an optional expected cause such as errBoom, then use require.ErrorIs. This prevents unrelated errors or removed wrapping from passing the test.

As per coding guidelines, “Prefer behavior-focused, table-driven unit tests with mocks; avoid tautological, stub, always-skipped, or coverage-only tests and target at least 85% coverage.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmd/azure/aks/update_kubeconfig_sdk_test.go` around lines 106 - 129, Update
the table-driven tests around executeAKSUpdateKubeconfigDirect to include an
expected error cause for configuration, manager, and authentication failures,
such as errBoom. Replace the broad require.Error assertion with require.ErrorIs
using that expected cause, while retaining the existing nil-credentials coverage
and ensuring each failure case verifies the wrapped underlying error.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@agent-skills/skills/atmos-auth/references/azure-acr-integration.md`:
- Around line 73-74: Update the ACR access-model statement to note that
registries are private by default but Standard and Premium registries may enable
anonymous pulls. Clarify that when ABAC repository permissions are enabled,
AcrPull and AcrPush do not apply, and document the applicable repository-scoped
roles instead.

In `@agent-skills/skills/atmos-auth/references/azure-aks-integration.md`:
- Around line 73-74: Update the kubeconfig documentation in the referenced
integration guide to specify Linux/macOS and Windows default paths, state that
ATMOS_XDG_CONFIG_HOME overrides XDG_CONFIG_HOME, and document the AKS override
precedence/options for --kubeconfig, ATMOS_KUBECONFIG, and KUBECONFIG.

In `@cmd/azure/aks/update_kubeconfig_sdk_test.go`:
- Around line 97-130: Update executeAKSUpdateKubeconfigDirect to treat a nil
whoami result the same as nil credentials before dereferencing
whoami.Credentials. Extend TestExecuteAKSUpdateKubeconfigDirect_Errors with a
"nil whoami" case that supplies a nil authentication result and expects an
error.

---

Nitpick comments:
In `@cmd/azure/aks/update_kubeconfig_sdk_test.go`:
- Around line 106-129: Update the table-driven tests around
executeAKSUpdateKubeconfigDirect to include an expected error cause for
configuration, manager, and authentication failures, such as errBoom. Replace
the broad require.Error assertion with require.ErrorIs using that expected
cause, while retaining the existing nil-credentials coverage and ensuring each
failure case verifies the wrapped underlying error.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: f8232e9c-e146-4197-9c04-3f48055ddc7c

📥 Commits

Reviewing files that changed from the base of the PR and between 4b2b4ac and 84d6bdd.

📒 Files selected for processing (9)
  • agent-skills/skills/atmos-auth/SKILL.md
  • agent-skills/skills/atmos-auth/references/azure-acr-integration.md
  • agent-skills/skills/atmos-auth/references/azure-aks-integration.md
  • cmd/azure/acr/login_more_test.go
  • cmd/azure/aks/update_kubeconfig_dispatch_test.go
  • cmd/azure/aks/update_kubeconfig_sdk.go
  • cmd/azure/aks/update_kubeconfig_sdk_test.go
  • cmd/azure/azure_test.go
  • pkg/auth/cloud/azure/coverage_extra_test.go
🚧 Files skipped from review as they are similar to previous changes (1)
  • cmd/azure/aks/update_kubeconfig_sdk.go

Comment thread agent-skills/skills/atmos-auth/references/azure-acr-integration.md Outdated
Comment thread agent-skills/skills/atmos-auth/references/azure-aks-integration.md Outdated
Comment thread cmd/azure/aks/update_kubeconfig_sdk_test.go
@atmos-pro

atmos-pro Bot commented Aug 13, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@atmos-pro

atmos-pro Bot commented Aug 13, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@github-actions

Copy link
Copy Markdown

These changes were released in v1.226.0-rc.7.

This branch was successfully deployed

1 active and 1 inactive deployments
preview — 21cadd22 Deployed Aug 13, 2026 by github-actions[bot]
screengrabs — 21cadd22 Deployed Aug 13, 2026 by aknysh via build #1378
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

minor New features that do not break anything size/xl Extra large size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants