2

Are there errors that Managed Service Identity (MSI) authentication that are transient and worthwhile retrying?

Reading through the implementation I can see HttpRequestException and Exception are absorbed by the framework and rethrown as AzureServiceTokenProviderException without an inner exception.

https://github.com/Azure/azure-sdk-for-net/blob/25adfede2b99391c29b5913fc289ff9511c9b26d/src/SdkCommon/AppAuthentication/Azure.Services.AppAuthentication/TokenProviders/MsiAccessTokenProvider.cs

I'm wondering (if any transient errors are possible), whether I'd need to inspect the exception message extracting the embedded http status code in the message and rethrow an e.g. my own AzureServiceTokenProviderTransientException capturing it in my retry logic.

My initial question is are there any known transient exceptions for MSI auth and secondly if there is any built in retry logic or recommended practices?

Alex KeySmith
  • 16,657
  • 11
  • 74
  • 152

1 Answers1

3

There error codes that MSI returns are documented here.

AzureServiceTokenProvider does include the exception details for cases where the HTTP response was not successful, so error codes like 404, 429, 500, will be included in the exception, along with an exception message. The exceptions that are absorbed are when the HTTP response was not received, e.g. when there is no MSI endpoint. The relevant code is here.

There is a retry logic recommended in the MSI documentation here. I have added a GitHub issue to implement this retry logic in the App Authentication library.

Varun Sharma
  • 568
  • 4
  • 5
  • Thanks Varun, that's an excellent resource for the MSI resource code, I find researching MSI tricky, as the documentation sometimes is under VM, sometimes AD, sometimes KeyVault. Ah yes I did spot that the status code gets written into the exception, but the trouble is that it is in the message text rather than a exception property to prone to breaking changes if the exception message format changed. Thanks for raising the github ticket, I'll add some thoughts to it. – Alex KeySmith Nov 14 '18 at 09:55