From 6a54396573302812fc6fe1ebbb7f14de0d63b533 Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Fri, 25 Sep 2026 21:02:06 +0200 Subject: [PATCH] small fix to table formatting --- .../secret-management/pmp-key-vault-integration.md | 1 + 1 file changed, 1 insertion(+) diff --git a/content/en/docs/private-platform/secret-management/pmp-key-vault-integration.md b/content/en/docs/private-platform/secret-management/pmp-key-vault-integration.md index d46b2b5f790..1dd8c4402a7 100644 --- a/content/en/docs/private-platform/secret-management/pmp-key-vault-integration.md +++ b/content/en/docs/private-platform/secret-management/pmp-key-vault-integration.md @@ -94,6 +94,7 @@ This is the managed identity tied to a specific environment. It is created autom This identity not a Key Vault access identity. It allows the Mendix Operator to automatically create the UAMI and connect it to an `azure-wi` storage or database plan. It is required for Approach A to work. | Property | Value | +| --- | --- | | **Azure roles required** | The *Managed Identity Contributor* role is required to create the per-environment UAMI and attach its federated credential. The issuer is the cluster OIDC URL, and the subject is the environment's ServiceAccount.
2. A *role-assignment-capable* role - for example, User Access Administrator or Role Based Access Control Administrator. This role must be scoped to the storage account or database resource used by the `azure-wi` plan, so the Operator can grant the newly created UAMI the required data-plane role, for example, Storage Blob Data Contributor for Blob Storage, or the equivalent Microsoft Entra role for Azure SQL or Postgres Flexible Server. | | **Scope** | The resource group containing the per-environment UAMIs, and the storage or database resources used by azure-wi plans | | **Granted by** | Customer (Infrastructure Team) |