Skip to content

Azure Container Repository Login Fails #3288

Description

@dbalseiro

Context

Starting with az CLI v2.30, token persistence to accessTokens.json was deprecated. However, func still relies on this file to authenticate against ACR. As a result, we are hitting errors such as:

open Azure access tokens: no such file or directory

This breaks ACR authentication flows that previously worked without any user-side changes.

Possible Approaches

  1. Call az acr login --expose-token or az account get-access-token to get a fresh token from az CLI whenever we want to access an Azure Container Repository
  2. Use the Azure SDK for Go to get default credentials and a fresh token (this would delegate authentication to supported mechanisms (including, but not limited to az CLI)

Related Work

I implemented a fix to validate the second approach here: stackbuilders#2

The PR avoids relying on accessTokens.json and instead fetches a fresh token using the SDK.
Happy to open a PR here and adjust it to better align with the project’s preferred direction.

Activity

  1. dbalseiro commented on Jan 13, 2026

    @dbalseiro
    Author

    /help

  2. knative-prow commented on Jan 13, 2026

    @knative-prow

    @dbalseiro:
    This request has been marked as needing help from a contributor.

    Please ensure the request meets the requirements listed here.

    If this request no longer meets these requirements, the label can be removed
    by commenting with the /remove-help command.

    Details

    In response to this:

    /help

    Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

  3. lkingland commented on Jan 21, 2026

    @lkingland
    Member

    I agree that azidentity.NewDefaultAzureCredential from the Azure SDK for Go is probably the right solution. That fits with the architectural direction of Azure (MSAL everywhere), works with managed identity providers in cloud environments, local az's, etc.

    Probably something like this:

     import (
         "github.com/Azure/azure-sdk-for-go/sdk/azcore/policy"
         "github.com/Azure/azure-sdk-for-go/sdk/azidentity"
     )
    
     cred, err := azidentity.NewDefaultAzureCredential(nil)
     token, err := cred.GetToken(ctx, policy.TokenRequestOptions{
         Scopes: []string{"https://containerregistry.azure.net/.default"},
     })
     return oci.Credentials{
         Username: "00000000-0000-0000-0000-000000000000",
         Password: token.Token,
     }

    Note ther's a bug in Existing PR: The stackbuilders/func PR #2 uses the wrong scope https://management.azure.com/.default. The correct ACR scope is https://containerregistry.azure.net/.default.

  4. self-assigned this
    on Jan 21, 2026
  5. dbalseiro commented on Jan 26, 2026

    @dbalseiro
    Author

    Good catch! ok I'll open a PR with the fix today. Thank you for your time!

  6. moved this from Active to Ready in Functions Traigeon Mar 24, 2026
  7. github-actions commented on Jun 17, 2026

    @github-actions
    Contributor

    This issue is stale because it has been open for 90 days with no
    activity. It will automatically close after 30 more days of
    inactivity. Reopen the issue with /reopen. Mark the issue as
    fresh by adding the comment /remove-lifecycle stale.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions