If your process requires configuring permissions to your worker node/kubelet so it can communicate with Azure services, you usually do that via managed identities. To retrieve your aks kubelet identity id, you can use the command below:
az aks show --resource-group rg-aks-configure --name aks-demo-cluster --query identityProfile.kubeletidentity.clientId -o tsv
The behavior of this command has been altered by the following extension: aks-preview
00000000-0000-0000-0000-000000000000