FairOps

Help CenterConectar cloud

Conectar Azure (Service Principal)

App Registration + Cost Management Reader. ~5 min.

Azure usa Service Principal com role limitada:

  1. Azure Portal → Azure Active Directory → App registrations → New registration
  2. Nome: "FairOpsReadOnly", Supported account types: single tenant
  3. Após criar, anote: Application (client) ID + Directory (tenant) ID
  4. Em "Certificates & secrets", crie novo client secret (validade 24 meses). Anote o valor.
  5. Em Subscriptions → [sua subscription] → Access control (IAM) → Add role assignment:
  6. - Role: Cost Management Reader
  7. - Assign access to: User, group, or service principal
  8. - Select: busque pelo nome "FairOpsReadOnly"
  9. Cole tenant_id, client_id e client_secret no wizard FairOps

Se você tem múltiplas subscriptions, adicione a role em cada uma.

Roles adicionais opcionais (para features avançadas): - Reader (para detectar recursos idle) — read-only, sem risco - Log Analytics Reader (para métricas Kubernetes)

#azure#service-principal

Outros artigos em Conectar cloud