Run a PowerShell Workload on a Local Kubernetes Cluster That Talks to Microsoft Graph
In the
last post, we wired up workload identity on an Azure Arc-enabled Kubernetes cluster and pulled a secret out of Key Vault without a single credential going anywhere near the pod.
Which was very satisfying… and also completely useless, because all that pod did was print a secret to the console and then die.
So let’s fix that. I want to take the exact same trust relationship and put it behind something I would actually run - a PowerShell workload, on a schedule, doing real work against Microsoft Graph. No app registrations, no client secrets rotating every six months, no certificate quietly expiring at 2am on a Sunday.
Which was very satisfying… and also completely useless, because all that pod did was print a secret to the console and then die.
So let’s fix that. I want to take the exact same trust relationship and put it behind something I would actually run - a PowerShell workload, on a schedule, doing real work against Microsoft Graph. No app registrations, no client secrets rotating every six months, no certificate quietly expiring at 2am on a Sunday.
11 minutes to read




