Add configurable Azure Managed token resource IDs - #272
Conversation
Support explicit resource_id audiences and REGION_NAME defaults for government regions across clients, workers, and sandbox registration. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Custom-channel sandbox transports bypass resource ID validation and must validate values before the channel branch.
Review effort: Lite
Findings: None
What changed in this PR
Adds configurable Azure Managed token resource IDs with region-aware defaults, normalization, refresh/reconnect preservation, documentation, and tests.
Changes:
- Adds
resource_idsupport across clients, workers, and sandbox components. - Selects Azure Government defaults and normalizes token scopes.
- Updates tests, documentation, and changelog entries.
| File | Reviewed changes |
|---|---|
tests/durabletask-azuremanaged/test_sandboxes_extension.py |
Sandbox audience and reconnect tests. |
tests/durabletask-azuremanaged/test_resource_id.py |
Defaults, overrides, normalization, and refresh tests. |
examples/sandboxes/README.md |
Sandbox audience configuration documentation. |
durabletask-azuremanaged/durabletask/azuremanaged/worker.py |
Worker resource ID support. |
durabletask-azuremanaged/durabletask/azuremanaged/preview/sandboxes/worker.py |
Audience preservation across reconnects. |
durabletask-azuremanaged/durabletask/azuremanaged/preview/sandboxes/transport.py |
Sandbox transport audience handling. |
durabletask-azuremanaged/durabletask/azuremanaged/preview/sandboxes/client.py |
Sandbox client resource ID support. |
durabletask-azuremanaged/durabletask/azuremanaged/internal/durabletask_grpc_interceptor.py |
Token audience forwarding. |
durabletask-azuremanaged/durabletask/azuremanaged/internal/access_token_manager.py |
Audience resolution and normalization. |
durabletask-azuremanaged/durabletask/azuremanaged/client.py |
Sync and async client configuration. |
durabletask-azuremanaged/CHANGELOG.md |
User-facing change documentation. |
docs/getting-started.md |
Authentication configuration documentation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Document caller-created credentials, anonymous authentication, and the sandbox managed identity exception. No authority-host SDK option is needed. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
andystaples
left a comment
There was a problem hiding this comment.
Reviewed for correctness, API compatibility, and documentation consistency. No actionable findings.
Resolve the Unreleased changelog conflict by retaining resource audience configuration and the incoming asynchronous Azure Blob payload fix. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Token audience selection at a glanceExplicit resource IDs override region defaults. Without an explicit value, case-insensitive Authority stays on the caller-provided credential; sandbox managed identity uses the hosting environment. Neither |

Summary
resource_idconfiguration to the sync/async Azure Managed clients, worker, and preview sandbox client and worker.https://durabletask.azure.uswhenREGION_NAMEstarts withusgovorusdod(case-insensitive); otherwise retainhttps://durabletask.io. Explicit values always take precedence./.defaultsuffix before requesting tokens; reject values that become empty. Resolve defaults per instance and preserve the selected audience across refreshes and sandbox registration reconnects.Authority host configuration
Source inspection confirms that all Azure Managed clients (
DurableTaskSchedulerClient,AsyncDurableTaskSchedulerClient, andSandboxActivitiesClient) and the standardDurableTaskSchedulerWorkeraccept caller-created credentials. They do not construct Azure Identity credentials.token_credentialis a required argument, but passingNonedisables SDK token authentication; it does not create a default credential. Custom implementations of Azure Core's credential protocols are also supported, not just classes from Azure Identity.No additional authority-host parameter is needed on these clients or the standard worker. They pass the supplied credential through to token managers, which call
get_token(scope)or await it. TheTokenCredential/AsyncTokenCredentialcontract has no supported per-request authority override. The SDK supplies the resource scope; the credential owns authority selection.Verified implementation paths at the feature commit:
ManagedIdentityCredential(client_id=...)using the injectedDTS_UMI_CLIENT_ID. Managed identities use their hosting environment's identity endpoint and ignore the authority setting, so no authority override is needed here either.Applications can explicitly configure the authority on their credential:
Omitting
authoritypreserves Azure Identity's default behavior, includingAZURE_AUTHORITY_HOSTwhere applicable. Credentials backed by developer tools use those tools' cloud configuration. The async client follows the same pattern withazure.identity.aio.DefaultAzureCredential.REGION_NAMEselects only the resource audience. Neither it norresource_idchanges the service endpoint or the credential's authority/cloud configuration. The usage documentation now explicitly explains credential ownership,Nonebehavior, custom credential protocols, and the sandbox managed identity exception in addition to the government authority example.Validation
Token requests are verified with recording credentials and local test doubles; live Azure Government authentication was not exercised.