The service account and application configuration were prepared for federated workload identity, matching the existing AKS security model and avoiding static Speech credentials. No live federation exchange was available to test.
- What worked
- It aligned cleanly with the repository's identity conventions and the Azure Identity SDK.
- What got in the way
- Deployment still required environment-specific workload identity identifiers, so authentication reliability remained unassessed.