Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
32 commits
Select commit Hold shift + click to select a range
646338d
feat(auth): add Azure AKS/ACR integrations mirroring EKS/ECR
osterman Jul 23, 2026
751c5d2
fix(security): remediate 4 open Dependabot alerts
osterman Jul 23, 2026
c9566a3
docs(auth): trim atmos-auth SKILL.md under the 500-line CI cap
osterman Jul 23, 2026
cd0a80f
[autocommit] formatting fixes
atmos-pro[bot] Jul 23, 2026
8c162b1
[autocommit] formatting fixes
atmos-pro[bot] Jul 23, 2026
380a604
docs(prd): fix editorconfig indentation in azure-aks-acr PRD
osterman Jul 23, 2026
0d18dc5
test(snapshots): add azure command to top-level --help golden files
osterman Jul 23, 2026
7a07257
fix(azure): address AKS and ACR review feedback
osterman Jul 23, 2026
02a9f0a
test(azure): address review feedback
osterman Jul 23, 2026
9c23951
fix(ci): restore Windows test environment
osterman Jul 24, 2026
ac25f17
fix(exec): honor components.packer/ansible.command overrides
osterman Jul 24, 2026
32ba80e
test(exec): clear command-resolution caches after the packer test too
osterman Jul 24, 2026
b358410
fix(security): remediate cel-go and postcss advisories
osterman Jul 24, 2026
7679509
[autocommit] formatting fixes
atmos-pro[bot] Jul 24, 2026
cc90996
Merge remote-tracking branch 'origin/main' into osterman/aks-acr-support
osterman Jul 30, 2026
2413bd9
Merge remote-tracking branch 'origin/main' into osterman/aks-acr-support
osterman Aug 4, 2026
c4bb292
Merge remote-tracking branch 'origin/main' into osterman/aks-acr-support
osterman Aug 6, 2026
b351c03
Merge branch 'main' into osterman/aks-acr-support
aknysh Aug 11, 2026
fb95d11
fix(auth): address CodeRabbit findings on AKS kubeconfig integration
osterman Aug 11, 2026
dc7f484
Merge remote-tracking branch 'origin/main' into osterman/aks-acr-support
aknysh Aug 11, 2026
1ee4179
Merge remote-tracking branch 'origin/main' into osterman/aks-acr-support
osterman Aug 11, 2026
8f3d79f
fix(auth): register azure integrations so azure/aks and azure/acr res…
aknysh Aug 11, 2026
3117ba8
docs(azure-aks): record live-cluster verification in PRD and blog
aknysh Aug 11, 2026
3cce647
test(auth): guard integration-kind registration via production import…
aknysh Aug 11, 2026
afad955
Merge remote-tracking branch 'origin/osterman/aks-acr-support' into o…
aknysh Aug 11, 2026
d7cb855
fix tests
aknysh Aug 11, 2026
01a64dd
increase test coverage, move AKS/ACR integration skills to '.claude/s…
aknysh Aug 11, 2026
3913bb3
Merge branch 'main' into osterman/aks-acr-support
aknysh Aug 11, 2026
e41b678
increase test coverage, move AKS/ACR integration skills to '.claude/s…
aknysh Aug 11, 2026
6238248
address comments
aknysh Aug 11, 2026
2b10533
Merge remote-tracking branch 'origin/main' into osterman/aks-acr-support
aknysh Aug 12, 2026
21cadd2
Merge branch 'main' into osterman/aks-acr-support
aknysh Aug 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions NOTICE
Original file line number Diff line number Diff line change
Expand Up @@ -1368,6 +1368,10 @@ MIT LICENSED DEPENDENCIES
License: MIT
URL: https://github.com/Azure/azure-sdk-for-go/blob/sdk/internal/v1.12.0/sdk/internal/LICENSE.txt

- github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/containerservice/armcontainerservice/v6
License: MIT
URL: https://github.com/Azure/azure-sdk-for-go/blob/sdk/resourcemanager/containerservice/armcontainerservice/v6.6.0/sdk/resourcemanager/containerservice/armcontainerservice/LICENSE.txt

- github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/resources/armresources
License: MIT
URL: https://github.com/Azure/azure-sdk-for-go/blob/sdk/resourcemanager/resources/armresources/v1.2.0/sdk/resourcemanager/resources/armresources/LICENSE.txt
Expand Down
29 changes: 15 additions & 14 deletions agent-skills/skills/atmos-auth/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
---
name: atmos-auth
description: "Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access"
Expand All @@ -13,7 +13,7 @@
OIDC, GitHub Actions, GCP Workload Identity Federation, Azure, Atmos Pro, and static credentials into a single configuration
model in `atmos.yaml`. Credentials are managed through providers (upstream authentication systems) and identities
(the roles and accounts obtained from those providers), with support for identity chaining, keyring-based
credential storage, and integrations like ECR, EKS, and GitHub STS.
credential storage, and integrations like ECR, EKS, ACR, AKS, and GitHub STS.

## Architecture Overview

Expand All @@ -22,7 +22,7 @@
1. **Providers** -- Upstream systems that issue initial credentials (SSO, SAML, OIDC, GCP ADC/WIF).
2. **Identities** -- Roles, permission sets, or accounts obtained from providers or chained from other identities.
3. **Keyring** -- Secure credential storage backend (system keyring, encrypted file, or in-memory).
4. **Integrations** -- Client-side credential materializations (ECR Docker login, EKS kubeconfig, GitHub STS).
4. **Integrations** -- Client-side credential materializations (ECR/ACR Docker login, EKS/AKS kubeconfig, GitHub STS).

```yaml
auth:
Expand Down Expand Up @@ -411,25 +411,24 @@
Keep this skill focused on the auth sections inside a profile, such as providers, identities, and
keyring settings.

## ECR Integrations
## ECR/ACR and EKS/AKS Integrations

ECR integrations auto-trigger on identity login when `auto_provision: true` (default):
Registry login (`aws/ecr`, `azure/acr`) and kubeconfig provisioning (`aws/eks`, `azure/aks`)
auto-trigger on identity login when `auto_provision: true` (default). `spec.registry` and
`spec.cluster` are single structs shared across both clouds — each integration's `kind` picks
which fields matter (see the per-cloud references below):

```yaml
auth:
integrations:
dev/ecr:
kind: aws/ecr
via:
identity: dev-admin
spec:
auto_provision: true
registry:
account_id: "123456789012"
region: us-east-2
dev/ecr: { kind: aws/ecr, via: { identity: dev-admin }, spec: { registry: { account_id: "123456789012", region: us-east-2 } } }
dev/acr: { kind: azure/acr, via: { identity: azure-dev }, spec: { registry: { name: myregistry } } }
dev/eks: { kind: aws/eks, via: { identity: dev-admin }, spec: { cluster: { name: dev-cluster, region: us-east-2 } } }
dev/aks: { kind: azure/aks, via: { identity: azure-dev }, spec: { cluster: { name: dev-cluster, resource_group: dev-rg } } }
```

Integration failures are non-blocking during `atmos auth login`. Use `atmos auth ecr-login` to retry.
Integration failures are non-blocking during `atmos auth login`; retry the per-integration login/update command.
Command details — AWS: [atmos-aws-ecr](../atmos-aws-ecr/SKILL.md), [atmos-aws-eks](../atmos-aws-eks/SKILL.md); Azure: [references/azure-acr-integration.md](references/azure-acr-integration.md), [references/azure-aks-integration.md](references/azure-aks-integration.md).

## GitHub STS Integration

Expand Down Expand Up @@ -495,3 +494,5 @@

- [references/providers-and-identities.md](references/providers-and-identities.md) -- Detailed provider and identity configuration patterns
- [references/commands-reference.md](references/commands-reference.md) -- Complete command reference for all auth subcommands
- [references/azure-aks-integration.md](references/azure-aks-integration.md) -- `azure/aks` integration: `atmos azure aks update-kubeconfig` / `token` (kubeconfig without `az`/`kubelogin`)
- [references/azure-acr-integration.md](references/azure-acr-integration.md) -- `azure/acr` integration: `atmos azure acr login` (Docker login without `az`)
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
# Azure ACR Integration (`azure/acr`)

Atmos logs Docker clients into Azure Container Registry via the `azure/acr` integration and the
`atmos azure acr login` command.

## Command

`atmos azure acr login` supports three modes:

```shell
# Named integration from auth.integrations
atmos azure acr login dev/acr

# All azure/acr integrations linked to an identity
atmos azure acr login --identity azure-dev

# Explicit registry login server using ambient Azure credentials
atmos azure acr login --registry myregistry.azurecr.io
```

Named-integration and identity modes use Atmos Auth. Explicit `--registry` mode uses ambient Azure
credentials (the Azure SDK default credential chain: environment variables, managed identity,
workload identity, Azure CLI).

## Configuration

Configure ACR integrations under `auth.integrations` with `kind: azure/acr`. Providers and
identities are the standard Azure Auth building blocks (see the main skill and
[providers-and-identities.md](providers-and-identities.md)):

```yaml
auth:
providers:
azure-device-code:
kind: azure/device-code
spec:
tenant_id: 00000000-0000-0000-0000-000000000000

identities:
azure-dev:
kind: azure/subscription
via:
provider: azure-device-code
principal:
subscription_id: 11111111-1111-1111-1111-111111111111

integrations:
dev/acr:
kind: azure/acr
via:
identity: azure-dev
spec:
auto_provision: true
registry:
name: myregistry
```

`spec.registry` is the same struct used by `aws/ecr` integrations (`account_id`, `region` for AWS;
`name`, `tenant_id` for Azure) — only the fields relevant to the integration's `kind` matter.
Login server = `{name}.azurecr.io`.

## Guidance

- Prefer named integrations for stable registries; they make the registry name and identity
explicit in `atmos.yaml`.
- Use `--identity` when the intent is "log in to every ACR registry attached to this identity."
- Use `--registry` for one-off registry login servers, or when a script intentionally uses ambient
Azure credentials instead of Atmos Auth.
- ACR credentials are written to Docker's config location, respecting `DOCKER_CONFIG` when set.
Set `DOCKER_CONFIG` first when the workflow needs isolated credentials.
- `spec.auto_provision: true` triggers ACR login during `atmos auth login`; set it to `false` for
registries that should only be logged in explicitly.
- `atmos azure acr login` has no `--public` mode (no ECR-Public equivalent) — it always
authenticates. ACR registries are private by default; grant the principal the built-in
`AcrPull`/`AcrPush` roles, or the repository-scoped roles when ABAC repository permissions are
enabled (those supersede the built-in `Acr*` roles). Standard/Premium registries can separately
enable anonymous pull, which needs no login.
- Installing Docker or related tools for a CI job is out of scope here — route tool installation to
the `atmos-toolchain` skill.
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
# Azure AKS Integration (`azure/aks`)

Atmos connects Azure AKS clusters to local Kubernetes tooling via the `azure/aks` integration and
two commands: `atmos azure aks update-kubeconfig` and `atmos azure aks token`. Unlike
`az aks get-credentials`, neither shells out to `az` nor requires the `kubelogin` binary.

## Commands

`atmos azure aks update-kubeconfig` writes kubeconfig entries for an AKS cluster — from a named
`auth.integrations` entry, or from an Atmos identity with explicit cluster details:

```shell
atmos azure aks update-kubeconfig --integration dev/aks
atmos azure aks update-kubeconfig --cluster-name dev-cluster --resource-group dev-rg --identity azure-dev
```

`atmos azure aks token` generates a Kubernetes `ExecCredential` token for kubectl. It is normally
invoked by kubectl from the generated kubeconfig, not run by humans:

```shell
atmos azure aks token --cluster-name dev-cluster --resource-group dev-rg --identity azure-dev
```

## Configuration

Configure an `azure/aks` integration under `auth.integrations`. Providers and identities are the
standard Azure Auth building blocks (see the main skill and
[providers-and-identities.md](providers-and-identities.md)):

```yaml
auth:
providers:
azure-device-code:
kind: azure/device-code
spec:
tenant_id: 00000000-0000-0000-0000-000000000000

identities:
azure-dev:
kind: azure/subscription
via:
provider: azure-device-code
principal:
subscription_id: 11111111-1111-1111-1111-111111111111

integrations:
dev/aks:
kind: azure/aks
via:
identity: azure-dev
spec:
cluster:
name: dev-cluster
resource_group: dev-rg
alias: dev-aks
```

`spec.cluster` is the same struct used by `aws/eks` integrations (`name`, `region` for AWS;
`name`, `resource_group`, `subscription_id` for Azure) — only the fields relevant to the
integration's `kind` matter.

## Guidance

- Prefer `--integration` when a named AKS integration exists; it centralizes cluster name,
resource group, alias, and identity selection.
- Use `--identity` with `--cluster-name` and `--resource-group` for ad hoc kubeconfig generation
through Atmos Auth.
- Only AAD-integrated clusters are supported (the modern default for AKS). Clusters using local
Kubernetes accounts are rejected with a clear error — there is no fallback to static
certificate-based auth.
- `subscription_id` is optional on `spec.cluster`; it defaults to the authenticated identity's
subscription. Set it explicitly only when the cluster's subscription differs from the identity's.
- The default kubeconfig path is XDG-based: `~/.config/atmos/kube/config` on Linux and macOS (macOS
is overridden to `~/.config`, not `~/Library/Application Support`), and
`%LOCALAPPDATA%\atmos\kube\config` on Windows. `ATMOS_XDG_CONFIG_HOME` (then `XDG_CONFIG_HOME`)
relocates the base directory.
- Override the target per invocation with `--kubeconfig`, or the `ATMOS_KUBECONFIG` / `KUBECONFIG`
environment variables (the flag takes precedence over the env vars). Do not hard-code paths unless
the repo already has a convention.
- Installing `kubectl` for a scripted job is out of scope here — route tool installation to the
`atmos-toolchain` skill.
2 changes: 1 addition & 1 deletion cmd/aws/eks/update_kubeconfig_sdk.go
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@ func executeEKSUpdateKubeconfigDirect(clusterName, region, kubeconfigPath, alias
return fmt.Errorf("%w: %w", errUtils.ErrEKSIntegrationFailed, err)
}

if _, err := kubeMgr.WriteClusterConfig(info, alias, identityName, "merge"); err != nil {
if _, err := kubeMgr.WriteClusterConfig(awsCloud.BuildKubeClusterInfo(info, identityName), alias, "merge"); err != nil {
return fmt.Errorf("%w: %w", errUtils.ErrEKSIntegrationFailed, err)
}

Expand Down
19 changes: 19 additions & 0 deletions cmd/azure/acr/acr.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
package acr

import "github.com/spf13/cobra"

// AcrCmd executes 'azure acr' CLI commands.
var AcrCmd = &cobra.Command{
Use: "acr",
Short: "Manage Azure Container Registry authentication and registry access",
Long: `Manage authentication for Azure Container Registry (ACR).

Login to ACR registries using named integrations, identity-linked integrations,
or explicit registry URLs. Credentials are written to Docker config for seamless
container workflows.

For more information, refer to the Atmos documentation:
https://atmos.tools/cli/commands/azure/acr-login`,
FParseErrWhitelist: struct{ UnknownFlags bool }{UnknownFlags: false},
Args: cobra.NoArgs,
}
Loading
Loading