Repository navigation
Azure Container Repository Login Fails #3288
Description
Activity
/help
Reacted by Luke Kinglandknative-prow commented
on Jan 13, 2026 knative-prowboton Jan 13, 2026 – with Knative ProwMore actions@dbalseiro:
This request has been marked as needing help from a contributor.Please ensure the request meets the requirements listed here.
If this request no longer meets these requirements, the label can be removed
by commenting with the/remove-helpcommand.Details
In response to this:
/help
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.
I agree that azidentity.NewDefaultAzureCredential from the Azure SDK for Go is probably the right solution. That fits with the architectural direction of Azure (MSAL everywhere), works with managed identity providers in cloud environments, local az's, etc.
Probably something like this:
import ( "github.com/Azure/azure-sdk-for-go/sdk/azcore/policy" "github.com/Azure/azure-sdk-for-go/sdk/azidentity" ) cred, err := azidentity.NewDefaultAzureCredential(nil) token, err := cred.GetToken(ctx, policy.TokenRequestOptions{ Scopes: []string{"https://containerregistry.azure.net/.default"}, }) return oci.Credentials{ Username: "00000000-0000-0000-0000-000000000000", Password: token.Token, }
Note ther's a bug in Existing PR: The stackbuilders/func PR #2 uses the wrong scope https://management.azure.com/.default. The correct ACR scope is https://containerregistry.azure.net/.default.
Good catch! ok I'll open a PR with the fix today. Thank you for your time!
Reacted by Luke Kinglandgithub-actions commented
on Jun 17, 2026 on Jun 17, 2026 – with GitHub ActionsContributorMore actionsThis issue is stale because it has been open for 90 days with no
activity. It will automatically close after 30 more days of
inactivity. Reopen the issue with/reopen. Mark the issue as
fresh by adding the comment/remove-lifecycle stale.
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsDone
Context
Starting with
azCLI v2.30, token persistence to accessTokens.json was deprecated. However,funcstill relies on this file to authenticate against ACR. As a result, we are hitting errors such as:This breaks ACR authentication flows that previously worked without any user-side changes.
Possible Approaches
az acr login --expose-tokenoraz account get-access-tokento get a fresh token from az CLI whenever we want to access an Azure Container RepositoryazCLI)Related Work
I implemented a fix to validate the second approach here: stackbuilders#2
The PR avoids relying on
accessTokens.jsonand instead fetches a fresh token using the SDK.Happy to open a PR here and adjust it to better align with the project’s preferred direction.