An App Service web app exposes the Kudu/SCM management site (a web console and file API), ships with publishing credentials that push code, and can carry a managed identity. Any of the three gives code execution or an identity token: Kudu is a shell, publishing credentials deploy a web shell, and the managed identity is the prize behind both.
What folds in here#
- Kudu and SCM: the management console for a web shell, file access, and environment secrets.
- Deployment credentials: publishing profiles that push code and read config.
- Managed identity: minting the app's managed-identity token.