Azure Identity Rust

作者 microsoft354361d83247MIT收錄於 2026年10月8日更新於 2026年10月8日

Azure Identity library for Rust. Microsoft Entra ID authentication for all Azure SDK clients. Triggers: "azure identity rust", "DeveloperToolsCredential", "authentication rust", "managed identity rust", "credential rust", "Entra ID rust".

AI 產生的概覽

指導 Rust 開發者使用 azure_identity 認證資訊,透過 Microsoft Entra ID 對 Azure SDK 用戶端進行身分驗證。

功能
此技能說明如何使用官方 azure_identity crate 讓 Rust 應用程式向 Azure 服務進行身分驗證。內容涵蓋安裝、環境變數,以及 DeveloperToolsCredential、ManagedIdentityCredential、ClientSecretCredential 等認證類型,並附有 Rust 程式碼範例。它也列出相依性管理、認證資訊處理與 SDK 模型相容性方面的最佳做法。
適用情境
當 Rust 應用程式需要向 Azure 服務進行身分驗證時使用,無論是本地開發、Azure 裝載的工作負載或服務主體情境。在選擇認證類型或設定 Entra ID 環境變數時也適用。
執行需求
需要 Rust 與 Cargo,以及 azure_identity、azure_core 和 tokio crate。服務主體身分驗證需要 AZURE_TENANT_ID、AZURE_CLIENT_ID 和 AZURE_CLIENT_SECRET;本地開發需要登入 Azure CLI 或 Azure Developer CLI。需要網路存取以取得 crate 並連線 Azure 服務。不包含指令碼。

Azure Identity library for Rust

Microsoft Entra ID authentication for Azure SDK clients.

Use this skill when:

  • An app needs to authenticate to Azure services from Rust
  • You need DeveloperToolsCredential for local development
  • You need ManagedIdentityCredential for Azure-hosted workloads
  • You need service principal auth with secret or certificate

IMPORTANT: Only use official azure_* crates published by the azure-sdk crates.io user. Do NOT use the deprecated azure_sdk_* crates (MindFlavor/AzureSDKForRust) or community crates. Official crates use underscores in names and none have version 0.21.0.

Note: The Rust SDK does not have DefaultAzureCredential. Use DeveloperToolsCredential for local development and ManagedIdentityCredential for production.

rust
// Incorrect in Rust: this type does not exist in azure_identityuse azure_identity::DefaultAzureCredential;

Installation

sh
cargo add azure_identity azure_core tokio

If your code uses azure_core types directly, add azure_core to Cargo.toml. If you only use service-crate re-exports, direct azure_core dependency is optional.

Environment Variables

bash
AZURE_TENANT_ID=<your-tenant-id>         # Required for service principal authAZURE_CLIENT_ID=<your-client-id>         # Required for service principal or user-assigned managed identityAZURE_CLIENT_SECRET=<your-client-secret> # Required for ClientSecretCredential

Authentication

DeveloperToolsCredential (Local Development)

Tries Azure CLI then Azure Developer CLI:

rust
use azure_identity::DeveloperToolsCredential;use azure_security_keyvault_secrets::SecretClient;
#[tokio::main]async fn main() -> Result<(), Box<dyn std::error::Error>> {    // Local dev: DeveloperToolsCredential. Production: use ManagedIdentityCredential.    let credential = DeveloperToolsCredential::new(None)?;    let client = SecretClient::new(        "https://<vault-name>.vault.azure.net/",        credential.clone(),        None,    )?;
    let secret = client.get_secret("secret-name", None).await?.into_model()?;    println!("Secret: {:?}", secret.value);    Ok(())}

Ensure you are logged in:

sh
az login        # Azure CLIazd auth login  # or Azure Developer CLI
OrderCredentialLogin Command
1AzureCliCredentialaz login
2AzureDeveloperCliCredentialazd auth login

ManagedIdentityCredential (Production)

For Azure-hosted resources (VMs, App Service, Functions, AKS):

rust
use azure_identity::ManagedIdentityCredential;
// System-assigned managed identitylet credential = ManagedIdentityCredential::new(None)?;

ClientSecretCredential (Service Principal)

For CI/CD pipelines and service accounts:

rust
use azure_identity::ClientSecretCredential;
let credential = ClientSecretCredential::new(    "<tenant-id>",    "<client-id>",    "<client-secret>",    None,)?;

Credential Types

CredentialUse Case
DeveloperToolsCredentialLocal development — tries CLI tools
ManagedIdentityCredentialAzure VMs, App Service, Functions, AKS
WorkloadIdentityCredentialKubernetes workload identity
ClientSecretCredentialService principal with secret
ClientCertificateCredentialService principal with certificate
AzureCliCredentialDirect Azure CLI auth
AzureDeveloperCliCredentialDirect azd CLI auth
AzurePipelinesCredentialAzure Pipelines service connection
ClientAssertionCredentialCustom assertions (federated identity)

Best Practices

  1. Use cargo add to manage dependencies, never edit Cargo.toml directly. Add and remove Rust SDK dependencies with cargo commands instead of manual manifest edits.
  2. Add azure_core only when importing azure_core types directly. If your code imports azure_core::http::Url, azure_core::http::RequestContent, or azure_core::error::ErrorKind, include azure_core; otherwise a direct dependency is optional.
  3. Use DeveloperToolsCredential for local dev, ManagedIdentityCredential for production — Rust does not provide a single DefaultAzureCredential type
  4. Never hardcode credentials — use environment variables for service principals
  5. Clone credentials — pass credential.clone() when constructing multiple clients; credentials are Arc-wrapped
  6. Reuse clients — clients are thread-safe; create once, share across tasks
  7. Assign RBAC roles — ensure the identity has appropriate roles for the target service (e.g., "Key Vault Secrets User" for secret reads)
  8. Run cargo clippy -- -D warnings when the prompt, eval, or CI expects lint-clean output; Rust trajectory graders can fail on style lints even after compiler errors are fixed
  9. Future-proof #[non_exhaustive] SDK models — when constructing SDK model/options structs, end the initializer with ..Default::default() (add #[allow(clippy::needless_update)]) and use a _ wildcard arm when matching SDK enums, so new service-added fields/variants don't break your build

Reference Links

來源與署名

來源:microsoft/skills位於.github/plugins/azure-sdk-rust/skills/azure-identity-rust提交354361d

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架