Skip to content

[Webinar] What's new in Spacelift? Join the Spring 2026 Product Release Roundup

Register Now ➑️

Setting up Azure and GCP credentials for Spacelift IntentΒ»

Azure credentialsΒ»

  1. Get your tenant id.

    1
    2
        $ az account show --query 'tenantId'`
        "<YOUR-TENANT-ID>"
    
  2. Get your subscription id.

    1
    2
      $ az account subscription list --query '[].{name:displayName,id:id}'
        [ ... , { "id": "<YOUR-SUBSCRIPTION-ID>", "name": "..." }, ... ]
    
  3. Optionally, create a role (role.json).

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    16
        {
          "Name": "example-role”,
          "IsCustom": true,
          "Description": "example-role",
          "Actions": [
            "Microsoft.Resources/subscriptions/<ACTIONS…>"
          ],
          "NotActions": [],
          "DataActions": [],
          "NotDataActions": [],
          "AssignableScopes": [
            "/subscriptions/<YOUR-SUBSCRIPTION-ID>"
          ]
        }
    
        $ az role definition create --role-definition role.json
    
  4. Create a service principal.

    1
    2
    3
    4
    5
    6
    7
        $ az ad sp create-for-rbac --name "example-name" --role "example-role" --scopes "/subscriptions/<YOUR-SUBSCRIPTION-ID>"
        {
        "appId": "<YOUR-CLIENT-ID>",
        "displayName": "example-name",
        "password": "<YOUR-CLIENT-PASSWORD>",
        "tenant": "<YOUR-TENANT-ID>"
        }
    
  5. Get client id and client password from above and setup env vars.

    1
    2
    3
    4
      ARM_CLIENT_ID="<YOUR-CLIENT-ID>"
      ARM_CLIENT_SECRET="<YOUR-CLIENT-PASSWORD>"
      ARM_TENANT_ID="<YOUR-TENANT-ID>"
      ARM_SUBSCRIPTION_ID="<YOUR-SUBSCRIPTION-ID>"
    

Azure environment setup

Google credentialsΒ»

Configuring Google credentials for Intent follows the same steps as setting up GCP for Spacelift. Once configured, your Intent project environment should contain:

  • Environment variables:
    • GOOGLE_APPLICATION_CREDENTIALS β€” path to the JSON configuration file (e.g., /mnt/workspace/gcp.json).
    • GOOGLE_PROJECT β€” your GCP project name (optional).
  • Mounted files:
    • gcp.json β€” the JSON configuration file downloaded from GCP.
    • spacelift.oidc β€” automatically mounted by Spacelift.