<!-- llms-explorer concept facts · https://llms-explorer.com/tree/aks-workload-identity-atlas/ · pack 2026-10-02 · ~12093 tokens -->

# AKS Workload Identity Atlas

> Depth-first rabbithole dossier for AKS Workload Identity Atlas; source-anchored research pack.

Parent: [MongoDB Atlas on Azure](https://llms-explorer.com/tree/mongodb-atlas-on-azure/) · 5 facets · 69 facts · page: https://llms-explorer.com/tree/aks-workload-identity-atlas/

## How it works

- - **Inherited and not counted:** the WIF launch blog (both URL forms), `azure-kms-secretless`, and `https://www.mongodb.com/docs/atlas/workload-oidc/`. The parent extract already links that last page, so the claims marked † rest on an inherited page. Their content is still a child delta. - **New origins:** - Microsoft: S1–S10, Entra and AKS docs. Microsoft's only inherited page was the architecture baseline. - Kubernetes project: S11. - MongoDB: non-inherited driver, AKO and API docs, plus the spec repo. - An independent practitioner: S25. - **Result: four organisations.** Even if every inheri — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#7-independent-origin-gate-inherited-sources-excluded`
- 24. Atlas tells you to register a separate Entra app for workload access, apart from any Workforce app. Set its manifest `requestedAccessTokenVersion` to `2`. Atlas maps the app's OIDC metadata issuer to Issuer URI, the client ID to Client ID, and the Application ID URI to Audience. https://www.mongodb.com/docs/atlas/workload-oidc/ 25. Microsoft states that in v2.0 access tokens `aud` "is always the client ID of the API", a GUID. In v1.0 tokens it may be the resource URI. https://learn.microsoft.com/en-us/entra/identity-platform/access-token-claims-reference 26. The User Claim stays `sub`. Aut — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#d-atlas-idp-and-database-user-configuration-pattern-3`
- Generated 2026-10-02 by `/rabbithole` (mechanism brief). Parent context: MongoDB Atlas on Azure. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md`
- **Out of scope:** Workforce (human) OIDC, LDAP, Private Link, Key Vault BYOK internals, and Atlas Kubernetes Operator (AKO) CRDs. Those are sibling frontier items. Each appears here only where it marks a boundary of this mechanism. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#scope`

## Measurements and reference values

- | # | Topic | Position A | Position B | Position C | |---|---|---|---|---| | 68 | **Atlas IdP Audience on Pattern 3** | Parent: `api://AzureADTokenExchange` | Atlas docs: the Application ID URI (S14†). M22 follows this. | Microsoft says v2 `aud` is the client-ID GUID (S5). The practitioner says only the GUID worked (S25). P reads this as: the Atlas page may assume URI = GUID. | | 69 | **Which principal Atlas sees for "AKS built-in"** | Atlas table: "AKS → Azure Managed Identity", tokens "from the Azure metadata server" (S14†) | Driver spec: `k8s` sends the raw SA token (`iss` = cluster issuer, — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#3-disagreements-side-by-side-not-resolved`
- | Topic | Source A | Source B | |---|---|---| | How an AKS pod gets its Atlas token | Atlas lists AKS as **built-in** auth with principal type "Azure Managed Identity" and says tokens come "from the Azure metadata server". https://www.mongodb.com/docs/atlas/workload-oidc/ | PyMongo puts AKS under "Other Azure Environments", which needs a **callback** with `azure-identity`, or under `ENVIRONMENT=k8s`, which reads the projected token file and not IMDS. https://www.mongodb.com/docs/languages/python/pymongo-driver/current/security/authentication/oidc.md · Microsoft: Workload ID uses the Entra v2 e — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#unresolved-disagreements-side-by-side`
- **Verdict:** `BUDGET_EXHAUSTED`. This is a soft stop, not saturation, because the rate never fell below 5%. One or two more passes would likely still pay off on: - an end-to-end test or third-party write-up of `ENVIRONMENT=k8s` against Atlas on AKS (which issuer and audience Atlas accepts); - the AKO release dates; - whether the Workload ID IMDS proxy sidecar (`azure.workload.identity/inject-proxy-sidecar`) makes driver `ENVIRONMENT=azure` work in a pod. That route is plausible from claims 19 and 23 but untested. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#depth-pass-curve`
- - **Which principal Atlas sees for "AKS built-in" auth.** Atlas's built-in-auth table lists "Kubernetes → Azure Kubernetes Service → Azure Managed Identity" (https://www.mongodb.com/docs/atlas/workload-oidc/). The driver spec says `ENVIRONMENT=k8s` sends the raw projected Kubernetes token (https://raw.githubusercontent.com/mongodb/specifications/master/source/auth/auth.md). That token's `iss` is the per-cluster AKS issuer and its `sub` is `system:serviceaccount:...`, not a managed-identity object ID (claims 11 and 13). If that is right, Path K would need an Atlas IdP whose Issuer URI is the AK — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#unresolved-disagreements`
- **Sibling concepts surfaced but not researched:** AKS identity bindings (preview); External Secrets Operator with Azure Key Vault workload-identity auth; Atlas Admin API service accounts and their secret lifecycle; GKE and EKS equivalents of the driver `k8s` provider; Atlas Workforce OIDC with Entra ID. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#8-sources`
- - AKS identity bindings (preview) as a concept in its own right. - External Secrets Operator + Azure Key Vault workload-identity auth for AKO credentials. - Atlas Service Accounts (OAuth client-credentials) as the AKO Admin-API credential. - GKE/EKS equivalents of the driver `k8s` provider. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#handoffs-siblings-surfaced-not-researched`
- | Pass | Focus | New atomic claims | Running total | New-info rate | |---|---|---|---|---| | 0 | Shared sources plus parent extract | 5 | 5 | 100% | | 1 | Primary docs: AKS Workload ID, Atlas workload-oidc, driver auth spec | 24 | 29 | 83% | | 2 | Boundaries and limits: Kubernetes, the webhook project, Entra FIC considerations, OIDC issuer, Admin API | 11 | 40 | 28% | — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#saturation-record`
- 1. **What goes in the Atlas IdP Audience field.** - Parent skill: `api://AzureADTokenExchange`. - Atlas docs: the Application ID URI (https://www.mongodb.com/docs/atlas/workload-oidc/). - Practitioner blog: the client-ID GUID, because v2 `aud` is the GUID. It reports that the URI fails (https://blog.saintmalik.me/mongodb-passwordless-auth-aks/). - Microsoft: v2 `aud` is always the API's client ID (https://learn.microsoft.com/en-us/entra/identity-platform/access-token-claims-reference). - Reading: each value fits a different pattern. `api://AzureADTokenExchange` is right only for pattern 2, whe — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#unresolved-disagreements-kept-side-by-side`
- No role reached two consecutive passes below 5%, so the verdict is **`BUDGET_EXHAUSTED`**. One or two more passes would likely pay off on: 1. a live decode of an Entra v2 token from a managed identity through a FIC (`aud` and `sub`), which settles disagreements 68 and 72; 2. Pattern 2 against a real Atlas IdP (issuer, JWKS reachability, audience), which settles disagreements 69 and 71; 3. the proxy sidecar with a MongoDB driver (disagreement 70); 4. fetching S26 (disagreement 74); 5. AKO 2.1.0 and 2.6.0 release dates. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#6-saturation-record`
- - **Independent sources / hosts used (new for this child):** mongodb.com docs (Atlas, PyMongo, AKO), raw.githubusercontent.com (mongodb/specifications, mongo-python-driver), learn.microsoft.com (2 pages), azure.github.io (azure-workload-identity), api.github.com (Azure/AKS releases). That is 5 hosts. - **Organisational independence is partial.** All sources come from **two vendors**, MongoDB and Microsoft. This run read no third-party or standards source; the Kubernetes projected-token spec was cited only through Microsoft. The 3-independent-source gate is **met on hosts but not on organisatio — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#quality-gate`
- | Pass | Focus | New atomic claims | Running total | New-info rate | |---|---|---|---|---| | 0 | Shared cache (WIF launch blog) | 3 | 3 | 100% | | 1 | Driver spec, Atlas WIF docs, PyMongo | 17 | 20 | 85% | | 2 | Microsoft WI overview, pod-identity history, AKS GA | 12 | 32 | 38% | | 3 | AKO auth, secret storage, oidcAuthType | 5 | 37 | 14% | — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#depth-pass-curve`
- **Verdict: `BUDGET_EXHAUSTED` (soft stop). This is not `SATURATED-DEPTH`.** No role ran two passes in a row below 5% new information. The cross-report pass still added about 8% new claims. What remains mostly needs a live JWT decode against an Atlas IdP, not more reading. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md`
- Verdict: **BUDGET_EXHAUSTED (soft stop), not SATURATED-DEPTH.** The rate was still 28% at pass 2. One or two more passes look likely to pay off, aimed at the Path K Atlas IdP configuration and the Entra managed-identity `sub` value. The tool tier blocked search, scrape and Bash, so all evidence came from direct WebFetch of known URLs. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#saturation-record`
- Stop: BUDGET_EXHAUSTED. The curve is falling but not below the 5% threshold. A third pass that tests pattern 2 against a live Atlas IdP (JWKS reachability, `sub` format) would likely still add claims. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#pass-log-new-information-rate`

## Problems, failure modes and limitations

- - **In scope:** an AKS pod authenticating to Atlas with `MONGODB-OIDC` through Entra Workload ID. That covers the token paths, the configuration each party needs, the invariants that must hold, token lifetimes, the limits, how the design evolved, and which credentials AKO can and cannot drop. - **Out of scope:** Workforce OIDC, LDAP, Private Link, BYOK internals, other clouds, and AKS identity bindings as a concept of its own. These go to the handoff list. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#1-scope`
- 42. The projected token's `expirationSeconds` defaults to 3600 on AKS. It can be set from 3600 to 86400 with the `azure.workload.identity/service-account-token-expiration` annotation. A pod annotation overrides a service-account annotation. [M25, H20, P12] S1 43. Kubernetes enforces a minimum of 600 s. The kubelet refreshes the token at 80% of its TTL or after 24 h, whichever comes first. [M26] S11 44. An Entra token expires 24 h after issue, independent of the SA token. [M27, H20, E22] S1 45. The driver caches one token per `MongoClient`. It allows one provider call at a time, at least 100 ms — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#d-lifetimes-caching-and-rotation`
- 1. **Audience.** `api://AzureADTokenExchange` is the audience of the **Kubernetes** token that Entra consumes. It is the Atlas audience only on Pattern 2, and Pattern 2 also breaks under identity bindings. On Pattern 3 it is wrong; see disagreement 68. [M40, H, E3, P] 2. **"Omit `TOKEN_RESOURCE`"** is true only for `ENVIRONMENT:k8s`. `azure` requires it and calls IMDS. [M6, H, E7] 3. **AKO and the Admin API "without long-lived credentials"** is disconfirmed. Workload ID can only fetch AKO's API key or SA secret from Key Vault through ESO. It cannot replace the secret. [M38, H34–36, E29–31, P31 — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#4-corrections-to-inherited-parent-facts`
- 19. Only pods labelled `azure.workload.identity/use: "true"` are mutated. Without the label, the pod gets no `AZURE_FEDERATED_TOKEN_FILE` and no token volume. AKS calls the labelled mode "Fail Close"; unlabelled pods "fail after they're restarted" — https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview 20. If you change a service-account annotation, you must restart the pod for the change to take effect — https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview 21. Kubernetes refreshes the projected token in place. Apps must re-read `AZURE_FEDERATED_TOKEN_FILE` o — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/edge-cases.md#d-aks-entra-failure-modes`
- 1. Microsoft deprecated the open-source Azure AD (Microsoft Entra) pod-managed identity project on **2022-10-24** and archived it in **September 2023**. https://learn.microsoft.com/en-us/azure/aks/use-azure-ad-pod-identity 2. Microsoft patched and supported the AKS Pod Identity managed add-on **through September 2025** so customers could move to Workload ID. https://learn.microsoft.com/en-us/azure/aks/use-azure-ad-pod-identity 3. Pod identity worked by intercepting IMDS: an NMI DaemonSet on each node redirected IMDS token requests to itself and fetched Entra tokens for the pod. https://learn.m — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#a-timeline-evolution`
- 15. AKS Workload ID needs AKS 1.22+ and Azure CLI 2.47.0+ on Standard clusters. https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview 16. The AKS cluster is the token issuer. Entra ID fetches the cluster's `{IssuerURL}/.well-known/openid-configuration` and `{IssuerURL}/openid/v1/jwks` to verify the projected service-account token before exchanging it for an Entra token. https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview 17. The mutating webhook mutates only pods labelled `azure.workload.identity/use: "true"`. It injects the projected token volume and sets ` — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#b-mechanism-deltas-specific-to-atlas-on-aks`
- - **Parent:** "For AKS federated credentials the audience is `api://AzureADTokenExchange` — ensure the Atlas IDP audience field matches." **Limit:** that audience belongs to the Kubernetes service-account token used for the Entra exchange (claim 32). Atlas's documented Azure setup uses the Entra app's Application ID URI as the audience (claim 28). The parent rule holds only on the raw-token `ENVIRONMENT=k8s` path, and fails under identity bindings (claim 33). - **Parent:** "For AKS with Workload Identity, omit `TOKEN_RESOURCE` — the driver reads the token from the OIDC file projected into the — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#corrections-to-inherited-parent-facts`
- 1. Two different wiring patterns exist. Most write-ups blur them together. - **Path E (Entra token):** the pod exchanges its Kubernetes token for a Microsoft Entra access token. It then presents that Entra token to Atlas. - **Path K (raw Kubernetes token):** the driver reads the projected Kubernetes service-account token from disk. It sends that token to Atlas unchanged. Sources: https://www.mongodb.com/docs/languages/python/pymongo-driver/current/security/authentication/oidc/ and https://raw.githubusercontent.com/mongodb/specifications/master/source/auth/auth.md 2. Path E is the pattern Mongo — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#a-the-two-token-exchange-paths`
- 18. The FIC issuer must match the token's `iss` claim. The FIC subject must match the token's `sub` claim. No FIC field accepts wildcards. Leading or trailing whitespace in `iss` blocks the exchange. https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-considerations 19. A wrong FIC subject saves without any error. The failure appears only when a token exchange is attempted. https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-considerations 20. A FIC has exactly one audience. The recommended value is `api://AzureADTokenExchange`, and the — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#c-invariants-all-must-hold-or-authentication-fails`
- 32. Atlas supports Workload Identity Federation only on dedicated clusters (M10 and above) running MongoDB 7.0.11 or later. https://www.mongodb.com/docs/atlas/workload-oidc/ 33. Only drivers support this mechanism; `mongosh` and Compass do not. Minimum versions: Java 5.1, C# 2.25, Go 1.17, PyMongo 4.7, Node 6.7, Kotlin 5.1, Rust 3.0, Scala 5.1. https://www.mongodb.com/docs/atlas/workload-oidc/ 34. A managed identity or app can hold at most 20 FICs. Each issuer+subject pair needs its own FIC, so one identity reaches at most 20 cluster/namespace/service-account combinations. Identity bindings (p — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#e-limits`
- 38. **Correction (Atlas Admin API):** The parent extract says Workload Identity lets the AKO pod "call the Atlas Admin API without storing long-lived credentials". The Admin API accepts only Atlas service-account OAuth tokens (client-credentials grant against `https://cloud.mongodb.com/api/oauth/token`, 1-hour lifetime, secret prefixed `mdb_sa_sk_`) or HTTP-digest API keys. No Entra or workload-identity method is listed. Workload ID therefore cannot replace AKO's Atlas credential Secret. https://www.mongodb.com/docs/atlas/configure-api-access/ 39. **Correction (Key Vault):** Atlas's own access — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#f-boundary-corrections-to-the-inherited-parent-facts`
- In scope: how a pod on Azure Kubernetes Service (AKS) with Microsoft Entra Workload ID authenticates to an Atlas cluster through `MONGODB-OIDC` (Atlas Workload Identity Federation). That covers the token path, Atlas IdP fields, driver modes, failure modes, and what Workload ID can and cannot do for the Atlas Kubernetes Operator (AKO). Out of scope: Workforce (human) OIDC, Private Link, Key Vault BYOK, other Azure services, EKS and GKE. The parent skill covers these. This report records only deltas and corrections against the inherited parent facts. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#scope`
- 1. Atlas supports Workload Identity Federation only on dedicated clusters (M10+) running MongoDB 7.0.11 or later, and only through selected drivers. https://www.mongodb.com/docs/atlas/workload-oidc/ 2. Only drivers can use this mechanism. `mongosh` and Compass do not support Workload Identity Federation, so ad-hoc debugging needs a driver script, not the shell. https://www.mongodb.com/docs/atlas/workload-oidc/ 3. Minimum driver versions are Java 5.1, C#/.NET 2.25, Go 1.17, PyMongo 4.7, Node 6.7, Kotlin 5.1, Rust 3.0 and Scala 5.1. https://www.mongodb.com/docs/atlas/workload-oidc/ 4. Correction — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#a-prerequisites-and-limits`
- 14. The AKS cluster is the token issuer. Entra fetches `{IssuerURL}/.well-known/openid-configuration` and `{IssuerURL}/openid/v1/jwks` to verify the token before it exchanges it. [M9–10, H16, P11] S1, S11 15. The issuer URL has the form `https://{region}.oic.prod-aks.azure.com/{tenant_id}/{uuid}`. The GUID is random and never changes, so each cluster has its own issuer. [M11] S2 16. Tokens are signed with RS256. Entra federation has been tested only with RS256. [M12] S3, S4 17. The token's `sub` has the form `system:serviceaccount:<ns>:<name>`. [M13] S11 18. The webhook mutates only pods label — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#b-aks-token-issuance`
- 50. Atlas supports WIF only on M10+ clusters running MongoDB 7.0.11 or later. M0, Flex and shared tiers are excluded. [M32, H11, E13, P1] S14† 51. Only drivers support WIF. `mongosh` and Compass do not, so you cannot reproduce a pod's login interactively. Minimum driver versions are Java 5.1, C# 2.25, Go 1.17, PyMongo 4.7, Node 6.7, Kotlin 5.1, Rust 3.0 and Scala 5.1. [M33, H30, E14, P2–3] S14† 52. One identity can hold at most 20 FICs, one per issuer+subject pair (cluster × namespace × SA). Identity bindings (preview) can lift this limit across clusters. [M34, H14, H21, E25, P6] S4, S1 53. Du — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#e-limits`
- 55. Microsoft deprecated pod-managed identity on 2022-10-24 and archived it in September 2023. The managed add-on was supported through September 2025. [H1–2] S6 56. Pod identity used an NMI DaemonSet to intercept IMDS. Its limits were 200 identities per cluster, Linux node pools only, VMSS-backed clusters only, and an ARP-spoofing risk under kubenet. [H3–4] S6 57. Workload ID dropped the CRDs and the IMDS-intercepting pods, and added Windows and non-Azure cluster support. [H5] S8 58. Workload ID reached GA in the Azure/AKS release `2023-04-09`, published 2023-04-20T21:54:31Z. A Tech Community — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#f-history`
- 62. The Atlas Admin API accepts only two credentials: - Atlas service-account OAuth tokens: a client-credentials grant against `https://cloud.mongodb.com/api/oauth/token`, 1-hour tokens, secret prefixed `mdb_sa_sk_`. - HTTP-digest API keys. No Entra or workload-identity method is listed. [M38] S18 63. AKO reads `orgId` plus either API keys or `clientId`/`clientSecret` from a Secret labelled `atlas.mongodb.com/type=credentials`. [H34, E29, P31] S20, S23, S24 64. AKO "must find the Kubernetes secrets it expects" and cannot read Key Vault directly. External Secrets Operator (ESO) or the Secrets S — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#g-ako-credentials`
- 67. These strings identify the failures: - `Authentication failed at finishAuthentication`: Atlas audience mismatch after a successful Entra exchange (P34, S25). - `AADSTS700212`: the projected token's audience does not match the FIC audience (S1). - `AADSTS70021`: FIC propagation, claim 53. - `Identity not found`: Pattern 1 on AKS, claim 9. - HTTP 409: concurrent FIC creation, claim 53. - "must have exactly one audience": claim 28. - error code 391: claim 46. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#h-failure-strings`
- - **In scope:** an application or operator pod running on AKS that authenticates to MongoDB Atlas using Microsoft Entra Workload ID, either through a MONGODB-OIDC driver or through the Atlas Kubernetes Operator (AKO). - **Out of scope:** Private Link, BYOK/Key Vault encryption, Workforce (human) federation, other clouds, and Azure services other than AKS. Those are separate frontier items. - **Parent facts:** I reuse parent facts only where this report corrects or limits them. Those places are marked **CORRECTION** or **LIMIT**. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/edge-cases.md#scope`
- 1. Two different audiences are involved. The projected Kubernetes service-account token that Entra exchanges uses the FIC audience `api://AzureADTokenExchange`. Microsoft calls this the recommended value, and the API enforces "exactly one audience" — https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-considerations 2. In a v2.0 Entra access token, `aud` "is always the client ID of the API" (a GUID). In a v1.0 token, `aud` can be either the client ID or the resource URI — https://learn.microsoft.com/en-us/entra/identity-platform/access-token-claims-reference 3. **C — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/edge-cases.md#a-which-token-reaches-atlas-the-core-ambiguity`
- 29. **CORRECTION** to the parent claim that Workload Identity lets the AKO pod "call the Atlas Admin API without storing long-lived credentials". AKO authenticates to the Admin API only with Programmatic API Keys or Atlas Service Accounts (`orgId`, `clientId`, `clientSecret`). It reads them from a Kubernetes Secret labelled `atlas.mongodb.com/type=credentials` — https://www.mongodb.com/docs/atlas/operator/v2.16/ak8so-service-accounts/ 30. AKO "must find the Kubernetes secrets it expects" and cannot read Key Vault directly. Workload Identity helps only indirectly: External Secrets Operator or t — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/edge-cases.md#e-ako-atlas-kubernetes-operator-limits`
- 9. Only pods labelled `azure.workload.identity/use: "true"` get the projected token volume and the injected env vars from the mutating webhook. Without the label, the pod fails after it restarts. https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview 10. The webhook sets `AZURE_FEDERATED_TOKEN_FILE`. Microsoft says to read the path from that variable and never hard-code `/var/run/secrets/azure/tokens/azure-identity-token`. https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview 11. The projected file holds a Kubernetes service-account token. The AKS cluster issue — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#b-token-mechanics-on-the-pod`
- Met. The claims draw on four hosts: mongodb.com (Atlas, AKO and driver docs), learn.microsoft.com (AKS, Entra), raw.githubusercontent.com (the MongoDB driver specification, a normative spec separate from the product docs) and blog.saintmalik.me (an independent practitioner write-up dated 2026-09-06, the disconfirming source). One caveat: the GitHub spec is published by MongoDB's own GitHub org, so it is not organisationally independent. The independent-source count rests on Microsoft and the practitioner blog. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/edge-cases.md#quality-gate`

## Comparisons and alternatives

- 1. A driver on AKS can reach Atlas through three patterns: - **Pattern 1:** `ENVIRONMENT:azure`, which uses IMDS. - **Pattern 2:** `ENVIRONMENT:k8s`, which sends the raw service-account token. M calls this "Path K". - **Pattern 3:** an `OIDC_CALLBACK` that returns an Entra token. M calls this "Path E". Most write-ups blur these together. [M1, P16–21] S12, S16 2. Pattern 3: the callback calls `DefaultAzureCredential`/`WorkloadIdentityCredential` with `.get_token(f"{audience}/.default")` and returns an **Entra** access token. PyMongo files AKS under "Other Azure Environments". [M2, H26, P21] S16 — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#a-driver-integration-patterns-on-aks`
- - **D1. What value goes in the Atlas Audience field.** The MongoDB docs say to use "the application ID URI value from your Azure Entra ID application registration" (https://www.mongodb.com/docs/atlas/workload-oidc/). Microsoft says a v2 token's `aud` "is always the client ID of the API" (https://learn.microsoft.com/en-us/entra/identity-platform/access-token-claims-reference). A practitioner reports that Atlas failed at `finishAuthentication` until the Audience was set to the client-ID GUID (https://blog.saintmalik.me/mongodb-passwordless-auth-aks/). With v2 tokens required (claim 4), the Micro — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/edge-cases.md#unresolved-disagreements`
- 16. **Pattern 1, `ENVIRONMENT:azure`:** the driver sends a GET to IMDS at `http://169.254.169.254/metadata/identity/oauth2/token?...&resource=<TOKEN_RESOURCE>&client_id=<username>`. The username is the managed identity's client ID. https://raw.githubusercontent.com/mongodb/specifications/master/source/auth/auth.md ; https://www.mongodb.com/docs/drivers/node/current/security/authentication/oidc/ 17. On an AKS pod, IMDS is the node's endpoint, not the pod's federated identity. One practitioner reports IMDS answering "Identity not found" under Workload ID and advises against `ENVIRONMENT:azure` o — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#c-the-three-driver-integration-patterns-on-aks`
- 26. The FIC issuer and subject must exactly match the token's `iss` and `sub`. No field accepts wildcards. Leading or trailing whitespace in `iss` blocks the exchange. [M18, E25] S4 27. A wrong FIC subject saves without error. The failure shows up only at exchange time. [M19, E27] S4 28. A FIC has exactly one audience. The API rejects other counts with "must have exactly one audience". [M20, E1] S4 29. Identity bindings (preview) change the default token's audience to `api://AKSIdentityBinding`. Using that token for direct federation fails with `AADSTS700212`. The fix is a second projected tok — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#c-invariants-authentication-fails-if-any-is-broken`
- 8. AKS Workload ID uses the Entra v2 token endpoint, "rather than the IMDS `resource` flow used by managed identity". A raw resource URI where a `<resource>/.default` scope belongs "can fail" — https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview 9. On AKS Workload ID, the built-in `ENVIRONMENT:azure` (IMDS) path failed with `Identity not found`, because the UAMI "lives behind the federated token file, not classic IMDS association". The fix was a custom callback using `@azure/identity` — https://blog.saintmalik.me/mongodb-passwordless-auth-aks/ 10. PyMongo documents a custom — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/edge-cases.md#b-imds-trap-and-the-driver-integration-you-pick`
- 13. **CORRECTION / precision** on "Dedicated Clusters on MongoDB 7.0 and above" (the 2024 GA blog). The current docs say "dedicated clusters (M10 and above) running MongoDB version 7.0.11 and above". M0, Flex and shared tiers are excluded — https://www.mongodb.com/docs/atlas/workload-oidc/ vs https://www.mongodb.com/company/blog/product-release-announcements/mongodb-introduces-workload-identity-federation-database-access 14. The 2024 GA blog listed only Java, C#, Node and Python, with Go "soon". The current docs list minimum versions: Java 5.1, C# 2.25, Go 1.17, PyMongo 4.7, Node 6.7, Kotlin 5 — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/edge-cases.md#c-atlas-side-boundaries`
- 25. The projected token's `expirationSeconds` defaults to 3600 on AKS and can be set from 3600 to 86400 with an annotation. A pod annotation overrides a service-account annotation. https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview 26. Kubernetes enforces a minimum `expirationSeconds` of 600. The kubelet refreshes the token at 80% of its TTL or after 24 hours, whichever comes first. Applications must re-read the file rather than cache it. https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/ and https://learn.microsoft.com/en-us/azure/aks/workl — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#d-token-lifetime-and-refresh`
- - AKS identity bindings (preview) for crossing the 20-FIC limit - AKO credential model (Atlas service accounts vs API keys) - GKE and EKS equivalents of Path K — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#handoffs-siblings-surfaced-not-chased`
- | Pass | Focus | New claims | Rate | |---|---|---|---| | 0 | Atlas WIF docs, driver spec, AKS overview | 19 | 100% | | 1 | Why/boundary: token issuer vs audience, IMDS on AKS, Entra claim semantics | 10 | 34% | | 2 | Disconfirm: practitioner blog, AKO credential model, ESO | 6 | 17% | — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#pass-log-new-information-rate`
- 1. I treated `https://www.mongodb.com/docs/atlas/workload-oidc/` as inherited because the parent extract links it. The gate passes either way. If the runner counts hosts rather than URLs, this choice does not change the outcome. 2. Parent corrections 1–4 and 6–7 call for edits to the parent skill text. Since tree and skill edits were out of scope, they are recorded here only. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#needs-input`

## Facts and statements

- Run: /rabbithole, 2026-10-02. Concept: **AKS Workload Identity Atlas** (an AKS pod authenticates to Atlas, and the Atlas Kubernetes Operator runs on AKS, using Microsoft Entra Workload ID). — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md`
- 34. AKO authenticates to the Atlas Admin API only with **API keys** (`orgId`/`publicApiKey`/`privateApiKey`) or **Atlas Service Accounts** (`clientId`/`clientSecret`) read from a Kubernetes Secret labelled `atlas.mongodb.com/type=credentials`. The docs list no OIDC, managed-identity or workload-identity option. https://www.mongodb.com/docs/atlas/operator/current/configure-ak8so-access-to-atlas.md 35. MongoDB's "secret-less" AKO pattern means only that the credential lives in an external store. A provisioning tool such as External Secrets Operator or the Secrets Store CSI Driver copies it into — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#c-ako-on-aks-and-workload-identity`
- - **Default to Pattern 3.** Atlas sees a managed-identity principal and one IdP serves every cluster. The costs are callback code and an extra Azure Identity version floor. - **Pattern 2** needs no code, but it requires one IdP per cluster, database users keyed to `system:serviceaccount:*` names, and an answer to disagreement 71. - **Avoid Pattern 1** on AKS. - **For AKO,** keep the Admin API secret in Key Vault behind ESO with workload identity, and rotate it within a year. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#5-operational-reading-from-p-kept-as-a-recommendation`
- - **In scope:** how AKS Workload ID and Atlas Workload Identity Federation evolved and meet; the token paths a pod on AKS can use to reach Atlas; how the Atlas Kubernetes Operator (AKO) relates to Workload ID; primary/official sources. - **Out of scope:** Private Link/DNS, Key Vault BYOK (except where AKO credentials touch it), Workforce (human) OIDC, Azure region map, IaC, and other sibling concepts of "MongoDB Atlas on Azure". - **Inherited parent facts** are not repeated as findings. They appear only where this run corrects or limits them (section "Corrections to inherited parent facts"). — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#scope`
- **In scope:** how a pod on Azure Kubernetes Service (AKS) authenticates to an Atlas cluster through Microsoft Entra Workload ID and Atlas Workload Identity Federation (`MONGODB-OIDC`). That covers the token chain, the configuration each party needs, the invariants that must hold, and the limits. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#scope`
- 31. Correction to the parent's "the AKO pod's service account should have Workload Identity … to call the Atlas Admin API without storing long-lived credentials". AKO reads `orgId` plus either API keys (`publicApiKey`/`privateApiKey`) or Service Account `clientId`/`clientSecret` from a Kubernetes Secret. The docs list no OIDC or Workload ID option for the Admin API. https://www.mongodb.com/docs/atlas/operator/v2.16/production-notes/ ; https://www.mongodb.com/docs/atlas/operator/v2.15/ak8so-service-accounts/ 32. Atlas Service Account secrets expire, with a TTL of at most one year. Atlas raises — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#e-ako-s-own-atlas-admin-api-credentials`
- - **Default choice:** pattern 3 (callback with Azure Identity). Atlas sees a managed-identity principal, and the IdP can be shared across clusters. The cost is application code, plus a second library with its own version floor. - **Pattern 2** needs no code. The costs are one Atlas IdP per AKS cluster issuer, database users keyed to `system:serviceaccount:*` names, and an open JWKS-reachability question (disagreement 4). - **Pattern 1** on AKS works only through a migration sidecar. Avoid it. - **AKO** still holds a secret for the Admin API. Keep it in Key Vault behind ESO with workload identi — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#operational-implications`
- 9. AKS Workload ID uses Kubernetes Service Account Token Volume Projection. In this model the AKS cluster is the token issuer. Entra ID uses OIDC discovery to fetch the issuer's public keys and verify the service-account token before it exchanges it. https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview 10. The issuer must serve `{IssuerURL}/.well-known/openid-configuration` and `{IssuerURL}/openid/v1/jwks`. https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview and https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/ 11. The AKS — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#b-the-aks-side-common-to-both-paths`
- - Atlas Workforce OIDC with Entra ID (human SSO). - External Secrets Operator with the Azure Key Vault workload-identity provider. - Atlas Administration API Service Accounts (secret lifecycle). - AKS identity bindings (preview). — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#handoffs-not-researched-here`
- S1 https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview S2 https://learn.microsoft.com/en-us/azure/aks/workload-identity-deploy-cluster S3 https://learn.microsoft.com/en-us/azure/aks/use-oidc-issuer S4 https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-considerations S5 https://learn.microsoft.com/en-us/entra/identity-platform/access-token-claims-reference S6 https://learn.microsoft.com/en-us/azure/aks/use-azure-ad-pod-identity S7 https://azure.github.io/azure-workload-identity/docs/installation/mutating-admission-webhook.html S8 https://azure.gi — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#8-sources`
- - https://www.mongodb.com/docs/atlas/workload-oidc/ - https://www.mongodb.com/docs/atlas/security-oidc/ - https://www.mongodb.com/company/blog/product-release-announcements/mongodb-introduces-workload-identity-federation-database-access - https://www.mongodb.com/docs/languages/python/pymongo-driver/current/security/authentication/oidc/ - https://www.mongodb.com/docs/atlas/operator/current/databaseuser-custom-resource/ - https://www.mongodb.com/docs/atlas/operator/v2.16/ak8so-service-accounts/ - https://www.mongodb.com/docs/atlas/operator/v2.16/ak8so-secret-storage/ - https://raw.githubusercont — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/edge-cases.md#sources`
- - https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview - https://learn.microsoft.com/en-us/azure/aks/use-azure-ad-pod-identity - https://azure.github.io/azure-workload-identity/docs/ - https://api.github.com/repos/Azure/AKS/releases/tags/2023-04-09 - https://techcommunity.microsoft.com/blog/appsonazureblog/general-availability-for-azure-active-directory-ad-workload-identity-on-aks/3798292 - https://raw.githubusercontent.com/mongodb/specifications/master/source/auth/auth.md - https://raw.githubusercontent.com/mongodb/mongo-python-driver/master/doc/changelog.rst - https://www.m — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/history.md#sources`
- - https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview (updated 2026-09-09) - https://learn.microsoft.com/en-us/azure/aks/workload-identity-deploy-cluster (updated 2026-08-01) - https://learn.microsoft.com/en-us/azure/aks/use-oidc-issuer (updated 2026-07-01) - https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-considerations (updated 2026-06-15) - https://azure.github.io/azure-workload-identity/docs/installation/mutating-admission-webhook.html - https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/ - https://www.mong — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/mechanism.md#sources`
- 34. An Atlas IdP audience mismatch shows up on the client as `Authentication failed at finishAuthentication`, even though the Entra token exchange succeeded. https://blog.saintmalik.me/mongodb-passwordless-auth-aks/ 35. `AADSTS700212` means the projected token audience does not match the FIC audience. Claim 14 describes the identity-bindings case. https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#f-observed-failure-strings`
- - https://www.mongodb.com/docs/atlas/workload-oidc/ - https://www.mongodb.com/blog/post/mongodb-introduces-workload-identity-federation-database-access - https://raw.githubusercontent.com/mongodb/specifications/master/source/auth/auth.md - https://www.mongodb.com/docs/drivers/node/current/security/authentication/oidc/ - https://learn.microsoft.com/en-us/azure/aks/workload-identity-overview - https://learn.microsoft.com/en-us/entra/identity-platform/access-token-claims-reference - https://blog.saintmalik.me/mongodb-passwordless-auth-aks/ - https://www.mongodb.com/docs/atlas/operator/current/atl — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#sources`
- The reports also used these URL variants, merged into the keys above: - S16 `.md` form: https://www.mongodb.com/docs/languages/python/pymongo-driver/current/security/authentication/oidc.md - S21 `.md` form: https://www.mongodb.com/docs/atlas/operator/current/ak8so-secret-storage.md - S21 v2.16 form: https://www.mongodb.com/docs/atlas/operator/v2.16/ak8so-secret-storage/ - S22 `.md` form: https://www.mongodb.com/docs/atlas/operator/current/atlasdatabaseuser-custom-resource.md - S22 alternate path: https://www.mongodb.com/docs/atlas/operator/current/databaseuser-custom-resource/ - S23 v2.15 form — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#8-sources`
- Inherited, not counted: - https://www.mongodb.com/blog/post/mongodb-introduces-workload-identity-federation-database-access - https://www.mongodb.com/company/blog/product-release-announcements/mongodb-introduces-workload-identity-federation-database-access - https://www.mongodb.com/docs/atlas/security/azure-kms-secretless/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/rabbithole-synthesis.md#8-sources`
- Met: three or more independent hosts were used, namely mongodb.com (with the mongodb/specifications spec on raw.githubusercontent.com), learn.microsoft.com, and blog.saintmalik.me. The independent blog dated 2026-09-06 served as the disconfirming source and contradicts both Atlas docs and the parent skill on audience. Caveats: the shared-source cache was used only for the WIF launch blog. Firecrawl, curl, and Bash fetches were denied in this session, so pages were read through WebFetch summaries with verbatim-quote prompts. Claims 20 and 30 rest partly on inference or summarized text. Re-verif — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aks-workload-identity-atlas-10a6052e32/reports/practice.md#quality-gate`

## Related concepts

- Atlas — is a part of AKS Workload Identity Atlas
- AKS — is a part of AKS Workload Identity Atlas
- Identity — is a part of AKS Workload Identity Atlas
- Workload — is a part of AKS Workload Identity Atlas
