Skip to content

saif-resources / identity

Creates the standard Forge identity pair for services: a User-Assigned Managed Identity (UAMI) for platform concerns and an Entra ID App Registration for runtime concerns.

Usage

module "identity" {
  source  = "app.terraform.io/SAIFCorp/resources/saif//modules/identity"
  version = "~> 1.0.0"

  providers = {
    azurerm               = azurerm
    azurerm.shared-services = azurerm.shared-services
    azuread               = azuread
  }

  context = module.environment.context
  name    = var.project_id

  # For services needing AI Hub + AI Search access
  ai_hub_roles = true

  # For services calling Document Intelligence prebuilt models on the AI Hub
  document_intelligence_roles = true

  # For Teams bots needing admin-consented Graph scopes
  grant_admin_consent = true
  api_permissions = [
    { api_name = "Microsoft Graph", permission_name = "User.Read", type = "Scope" }
  ]
}

Outputs

Name Description
identity Structured object with UAMI and App Registration references

Identity Object Shape

identity.uami_id / identity.uami_client_id / identity.uami_principal_id
identity.app_client_id / identity.app_object_id
identity.sp_principal_id / identity.sp_object_id
identity.client_secret_kv_ref   — @Microsoft.KeyVault() reference string
identity.client_secret_kv_uri   — versionless secret URI

Required Providers

  • azurerm (>= 4.0, < 5.0) — with azurerm.shared-services alias
  • azuread (>= 3.0, < 4.0)

Providers

Name Version
azurerm >= 4.0, < 5.0
azurerm.shared-services >= 4.0, < 5.0

Inputs

Name Description Type Default Required
ai_hub_roles Whether to grant AI Hub and AI Search roles to the service principal bool false no
api_permissions API permissions to request on the app registration
list(object({
api_name = string
permission_name = string
type = string
}))
[] no
context Platform context from the environment module any n/a yes
create_client_secret Whether to create a client secret for the app registration bool true no
document_intelligence_roles Whether to grant Document Intelligence data-plane access on the AI Hub to the service principal bool false no
enable_agents_sdk Whether to emit Connections__ServiceConnection__* app settings for the M365 Agents SDK bool false no
enable_oidc Whether to emit OpenIdConnectClientId_{tenant} / OpenIdConnectClientSecret_{tenant} app settings bool false no
grant_admin_consent Whether to grant admin consent for API permissions bool false no
microsoft_app_type Bot Framework app type — set to emit MicrosoftApp* app settings. Values: SingleTenant, MultiTenant. string null no
name Application name used for identity resources (e.g. project_id) string n/a yes
owners Map of Entra ID object IDs to set as application owners. Keyed by a stable name. Defaults to the current caller. map(string) {} no
redirect_uris Redirect URIs for the app registration (e.g. OAuth2 callback URLs) list(string) [] no
resource_group_location The Azure region for identity resources string n/a yes
resource_group_name The resource group for identity resources (UAMI) string n/a yes
visible_to_users Whether the enterprise application appears on users' My Apps page. Controls feature_tags.hide on the service principal. Defaults to hidden, which is correct for APIs, bots, and background consumers; set true only for apps users sign in to directly. bool false no
web_logout_url Post-logout redirect URL for the app registration string null no

Outputs

Name Description
app_settings Map of credential-related app settings, controlled by flag variables. Merge into webapp app_settings.
client_secret_value The app registration client secret value. Sensitive — use only where the actual value is required (e.g. Bot OAuth connections). Prefer identity.client_secret_kv_ref for app settings.
identity Identity bundle — UAMI + App Registration references (no sensitive values)

Resources

  • resource.azurerm_key_vault_secret.client_secret (/terraform-docs/modules/identity/main.tf#41)
  • resource.azurerm_role_assignment.acr_pull (/terraform-docs/modules/identity/main.tf#66)
  • resource.azurerm_role_assignment.app_configuration_reader (/terraform-docs/modules/identity/main.tf#76)
  • resource.azurerm_role_assignment.client_secret_reader (/terraform-docs/modules/identity/main.tf#50)
  • resource.azurerm_role_assignment.cognitive_services_openai_user (/terraform-docs/modules/identity/main.tf#128)
  • resource.azurerm_role_assignment.cognitive_services_user (/terraform-docs/modules/identity/main.tf#152)
  • resource.azurerm_role_assignment.otel_header_np_sp (/terraform-docs/modules/identity/main.tf#109)
  • resource.azurerm_role_assignment.otel_header_np_uami (/terraform-docs/modules/identity/main.tf#93)
  • resource.azurerm_role_assignment.otel_header_prod_sp (/terraform-docs/modules/identity/main.tf#117)
  • resource.azurerm_role_assignment.otel_header_prod_uami (/terraform-docs/modules/identity/main.tf#101)
  • resource.azurerm_role_assignment.search_index_data_reader (/terraform-docs/modules/identity/main.tf#136)
  • resource.azurerm_role_assignment.search_service_contributor (/terraform-docs/modules/identity/main.tf#144)
  • resource.azurerm_user_assigned_identity.main (/terraform-docs/modules/identity/main.tf#14)

View source on GitHub