Today resources deployed in CDF (Transformations, Cognite Functions etc), requires a client and secret. This is done through providing the secret either through cognite-toolkit or in the user interface.
However it is not possible to use Workload identity federation to be able to reach secrets in an Azure tenant from CDF. This is hindering the possibility of using a federated credential to retrieve keys from a key vault for instance.
Using a workload identity federation would be:
- More secure, as this does not require client / secrets
- Reduce workload on secret rotation
Check the
documentation
Ask the
Community
Take a look
at
Academy
Cognite
Status
Page
Contact
Cognite Support