イベントドリブンのサーバーレス コンピューティング プラットフォームを提供する Azure サービス。
Which identity retrieves a private packageUri for Azure Functions Flex Consumption Direct ARM OneDeploy?
We are designing a least-privilege deployment path for an Azure Functions Linux Flex Consumption app using Python 3.12.
The Function App has a System Assigned Managed Identity. Its private deployment Blob container is configured through functionAppConfig.deployment.storage with:
authentication.type = SystemAssignedIdentity
We want to call Direct ARM OneDeploy:
PUT https://management.azure.com/subscriptions/<subscription-id>/resourceGroups/<resource-group>/providers/Microsoft.Web/sites/<function-app>/extensions/onedeploy?api-version=<supported-version>
with:
{
"properties": {
"packageUri": "https://example.blob.core.windows.net/staging/package.zip",
"remoteBuild": true
}
}
The Blob is private and the URL contains no SAS token.
Microsoft documentation says that the Functions host must be able to access both the remote package source and the deployment container, but we could not find a public contract identifying the credential used to retrieve the remote packageUri.
Could the Azure Functions or App Service team clarify the following?
- Which identity retrieves a private
packageUri: the Function App System Assigned Managed Identity, the identity configured underdeployment.storage.authentication, a OneDeploy service identity, or another identity? - Does the
SystemAssignedIdentitydeployment-storage authentication apply to the remote package source, or only to the configured deployment container? - Is
Storage Blob Data Readerscoped to the source Blob/container sufficient? Are source read access and deployment-container write access evaluated separately? Can the source use a different container or Storage Account? - Does the Direct ARM caller need only:
Microsoft.Web/sites/extensions/write
Microsoft.Web/sites/extensions/read
and optionally Microsoft.Web/sites/read for target validation? Is Microsoft.Web/sites/publish/Action unnecessary for this ARM child-resource path?
- What is the formal response and terminal-state contract for:
GET /sites/<function-app>/extensions/onedeploy
Is /deploymentStatus/{deploymentStatusId} required or optional?
Our deployment principal must not read or write App Settings, retrieve publishing credentials, publish profiles, Function keys, Storage keys, generate SAS, modify RBAC, or access the Storage Data Plane. Package upload is handled by a separate identity.
We are specifically asking about Direct ARM OneDeploy, not SCM, Azure/functions-action, Azure CLI publish, or Core Tools publish. An answer from the Azure Functions/App Service team with an official specification or documentation link would be especially helpful.