Open
Description
Current situation
image creation script currently creates storage account with access key enable and generates the sas url for azure-init tarball based on the access key.
Impact
This might violate security compliance in some Azure organization.
Ideal future situation
image creation script should create storage account with access key disabled and generate sas using user delegation key