https://github.com/Azure-Samples/azure-service-operator-samples/blob/c1c6a78e6e68e82ee2d54a4225b2d7387f4a1413/cosmos-todo-list-mi/cosmos-app.yaml#L24 The pod needs the label `azure.workload.identity/use: "true"` to work correctly. This blocked me for a while testing this out.