Orkestia
Blog
Cloud Connections

Microsoft Azure

Connect an Azure subscription to your organization and unlock the azure.* workflow family — AKS, ACR, compute, networking, Key Vault, and storage

The azure.* family (~60 workflows) covers AKS, ACR, virtual machines, container apps, networking and DNS, Front Door, Key Vault, and blob storage — run against your subscription through a connection you grant.

What the grant is

An Azure connection is a service principal: an app registration in your Entra tenant with role assignments scoped to the subscription or resource groups you choose. Orkestia authenticates as that principal; its authority is the role assignments you made, and removing them (or disabling the app registration) severs access immediately.

Setting it up

  1. Read the prerequisites of the workflow family you're targeting (azure.aks.*, azure.acr.*, …) via get_workflow_prerequisites or the dashboard connection flow — the guide states the roles and scope required.
  2. In your tenant: create an app registration + client secret (or the credential form the guide specifies), and assign only the listed roles at the narrowest scope that works — a resource group beats the whole subscription.
  3. Create the org-scoped connection in Orkestia; validation runs a read-only check first.
Prefer resource-group scope over subscription scope, and separate principals per environment. Contributor on the whole subscription is the Azure equivalent of handing over the keys — the prerequisites guide never asks for more than the family needs.

What people run on it

  • AKS operations — azure.aks.* plus the cloud-agnostic kubernetes.* family once a cluster credential exists.
  • Registry + compute — azure.acr.*, azure.compute.*, azure.containerapps.*.
  • Edge + secrets — azure.frontdoor.*, azure.dns.*, azure.keyvault.*.
  • Runner capacity — runners provisioned on Azure consume this connection.

Browse the full family at reference.orkestia.dev/azure.