Azure AD client secret. Optional — when omitted, the integration falls back to Azure Workload Identity Federation, exchanging the Kubernetes-projected service-account JWT at AZURE_FEDERATED_TOKEN_FILE for an access token (no long-lived secret stored).
tokenstring
Static Bearer token for testing/development (optional, if provided this is used instead of OAuth2 authentication)