Which identity retrieves a private packageUri for Azure Functions Flex Consumption Direct ARM OneDeploy?

森川 佳彦 0 評価のポイント
2026-08-28T09:26:54.01+00:00

We are designing a least-privilege deployment path for an Azure Functions Linux Flex Consumption app using Python 3.12.

The Function App has a System Assigned Managed Identity. Its private deployment Blob container is configured through functionAppConfig.deployment.storage with:

authentication.type = SystemAssignedIdentity

We want to call Direct ARM OneDeploy:

PUT https://management.azure.com/subscriptions/<subscription-id>/resourceGroups/<resource-group>/providers/Microsoft.Web/sites/<function-app>/extensions/onedeploy?api-version=<supported-version>

with:

{
  "properties": {
    "packageUri": "https://example.blob.core.windows.net/staging/package.zip",
    "remoteBuild": true
  }
}

The Blob is private and the URL contains no SAS token.

Microsoft documentation says that the Functions host must be able to access both the remote package source and the deployment container, but we could not find a public contract identifying the credential used to retrieve the remote packageUri.

Could the Azure Functions or App Service team clarify the following?

  1. Which identity retrieves a private packageUri: the Function App System Assigned Managed Identity, the identity configured under deployment.storage.authentication, a OneDeploy service identity, or another identity?
  2. Does the SystemAssignedIdentity deployment-storage authentication apply to the remote package source, or only to the configured deployment container?
  3. Is Storage Blob Data Reader scoped to the source Blob/container sufficient? Are source read access and deployment-container write access evaluated separately? Can the source use a different container or Storage Account?
  4. Does the Direct ARM caller need only:
Microsoft.Web/sites/extensions/write
Microsoft.Web/sites/extensions/read

and optionally Microsoft.Web/sites/read for target validation? Is Microsoft.Web/sites/publish/Action unnecessary for this ARM child-resource path?

  1. What is the formal response and terminal-state contract for:
GET /sites/<function-app>/extensions/onedeploy

Is /deploymentStatus/{deploymentStatusId} required or optional?

Our deployment principal must not read or write App Settings, retrieve publishing credentials, publish profiles, Function keys, Storage keys, generate SAS, modify RBAC, or access the Storage Data Plane. Package upload is handled by a separate identity.

We are specifically asking about Direct ARM OneDeploy, not SCM, Azure/functions-action, Azure CLI publish, or Core Tools publish. An answer from the Azure Functions/App Service team with an official specification or documentation link would be especially helpful.

Azure Functions
Azure Functions

イベントドリブンのサーバーレス コンピューティング プラットフォームを提供する Azure サービス。


お客様の回答

質問作成者は回答に "承認済み"、モデレーターは "推奨" とマークできます。これにより、ユーザーは作成者の問題が回答によって解決したことを把握できます。