A VM you hold write rights over is both a code-execution target and a credential source. The management plane gives you execution without any stored credential (run command, an extension), and once you are on the box, the VM's attached managed identity hands out a subscription token from the metadata endpoint.
Pages#
- Run command:
runCommandfor SYSTEM or root execution with no credential. - Custom Script Extension:
extensions/writeto run code, including VMAccess to reset the admin password. - Managed identity: steal the VM identity's token from IMDS.
- User data: read cloud-init and user data for secrets, or write it to run at boot.