sdaf-gh-oidc-and-auth
Action-loop skill for authenticating the SDAF GitHub Actions workflows to Azure. Two independent layers must both be right: (1) `azure/login` uses an OIDC federated credential and reads `AZURE_ENVIRONMENT` + `AZURE_AUDIENCE`; (2) Terraform and Ansible authenticate separately via either a managed identity (`USE_MSI=true`, `MSI_ID`) or a service principal with `ARM_CLIENT_SECRET`, and always read `ARM_ENVIRONMENT`. This skill resolves `AADSTS7002381` (enterprise-claim tenant policy), `AADSTS7000215` / `AADSTS700016` (missing or expired `ARM_CLIENT_SECRET`), `AADSTS900382` (sovereign-cloud `ARM_ENVIRONMENT` not exported alongside ARM creds), and "`azure/login` succeeded but hit the wrong cloud". Invoke on Azure-login failures, OIDC federated-credential questions, MSI-vs-SPN choice, or sovereign-cloud identity configuration. Do NOT invoke for bootstrap mechanics or the setup utility (use `sdaf-gh-bootstrap`) or for the workflow catalogue (use `sdaf-gh-workflow-sequence`).
Quellinformationen
- Repository
- Azure/sap-automation-gh-bootstrap
- Letzte Quellaktivität
- 27. August 2026 um 03:13
- Erkannte Sprache von SKILL.md
- Englisch
- Sterne
- 1
- Forks
- 9
Installationsoptionen
Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.
Quelldateien prüfen
Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.