Skip to content

[confcom] managed-identity env allowlist missing APP_IDENTITY_ENDPOINT #10310

Description

@swibi-ttd

Describe the bug

We've noticed a newly injected environment variable APP_IDENTITY_ENDPOINT in our confidential container groups that aren't in the current allowlist.

internal_config.json's managedIdentity.environmentVariables currently lists only:

IDENTITY_API_VERSION
IDENTITY_HEADER
IDENTITY_SERVER_THUMBPRINT

(last updated 2026-04-17)

We've recently been seeing our deployments fail with the following error, despite no changes to our ARM template or CCE policy:

{"decision":"deny","reason":{"errors":["invalid env list: APP_IDENTITY_ENDPOINT"]}}

Workaround
Setting allow_environment_variable_dropping := true avoids the failure. Adding explicit env_rules for these variable names to our own containers does not help, as we suspect there are transient Azure-side containers that don't have this whitelisted.

Related command

az confcom

Errors

{"decision":"deny","reason":{"errors":["invalid env list: APP_IDENTITY_ENDPOINT"]}}

Issue script & Debug output

az deployment group create --name operator-control --resource-group $RG --parameters operator.parameters.json  --template-file operator.json
{"status":"Failed","error":{"code":"DeploymentFailed","target":"/subscriptions/XXX/resourceGroups/uid-enclave-test/providers/Microsoft.Resources/deployments/operator-control","message":"At least one resource deployment operation failed. Please list deployment operations for details. Please see https://aka.ms/arm-deployment-operations for usage details.","details":[{"code":"ResourceDeploymentFailure","target":"/subscriptions/XXX/resourceGroups/uid-enclave-test/providers/Microsoft.ContainerInstance/containerGroups/uid-operator-5.70.159-r0-azure-cc-1","message":"The resource write operation failed to complete successfully, because it reached terminal provisioning state 'Failed'.","details":[{"message":"failed to create containerd task: failed to create shim task: failed to create container e23c0e58dd1b4dcf37466e9c9986693c51cffd9dd0c8d762af041058cced4be1: guest RPC failure: container creation denied due to policy: {\"decision\":\"deny\",\"reason\":{\"errors\":[\"invalid env list: APP_IDENTITY_ENDPOINT\"]},\"truncated\":[\"input\"]};The container group provisioning has failed. Refer to 'DeploymentFailedReason' event for more details."}]},{"code":"ResourceDeploymentFailure","target":"/subscriptions/XXX/resourceGroups/uid-enclave-test/providers/Microsoft.ContainerInstance/containerGroups/uid-operator-5.70.159-r0-azure-cc-0","message":"The resource write operation failed to complete successfully, because it reached terminal provisioning state 'Failed'.","details":[{"message":"failed to create containerd task: failed to create shim task: failed to create container 8bcb921f25ca799fd2b6fa34a5505265f232dec0ebd03081efe0efa05d128bcf: guest RPC failure: container creation denied due to policy: {\"decision\":\"deny\",\"reason\":{\"errors\":[\"invalid env list: APP_IDENTITY_ENDPOINT\"]},\"truncated\":[\"input\"]};The container group provisioning has failed. Refer to 'DeploymentFailedReason' event for more details."}]}]}}

Deployment artefacts available here: https://github.com/IABTechLab/uid2-operator/releases/tag/v5.70.159-r0
We also tried adding APP_IDENTITY_ENDPOINT to env_rules but still ran into the same error: https://github.com/IABTechLab/uid2-operator/releases#release-v5.70.159-r4

Expected behavior

The deployment succeeds

Environment Summary

azure-cli 2.88.0 *

core 2.88.0 *
telemetry 1.1.0

Extensions:
resource-graph 2.1.1

Dependencies:
msal 1.36.0
azure-mgmt-resource 24.0.0

Python location '/opt/homebrew/Cellar/azure-cli/2.88.0/libexec/bin/python'
Config directory '/Users/sean.wibisono/.azure'
Extensions directory '/Users/sean.wibisono/.azure/cliextensions'

Python (Darwin) 3.14.6 (main, Jun 10 2026, 10:03:53) [Clang 21.0.0 (clang-2100.0.123.102)]

Legal docs and information: aka.ms/AzureCliLegal

<><><>

also upgraded to 2.90.0 but still seeing the same error message

Additional context

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Service AttentionThis issue is responsible by Azure service team.bugThis issue requires a change to an existing behavior in the product in order to be resolved.customer-reportedIssues that are reported by GitHub users external to the Azure organization.extension/confcomIssues for the confcom extension

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions