Bird
Raised Fist0
Azurecloud~5 mins

Environment variables and configuration in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Apps often need settings like passwords or URLs that can change without changing the app code. Environment variables let you store these settings outside the app so you can update them easily and keep secrets safe.
When you want to keep database passwords separate from your app code to avoid exposing them.
When you need to change API keys or URLs without rebuilding your app.
When running the same app in different places like testing and production with different settings.
When you want to avoid hardcoding sensitive information in your app files.
When you want to manage app settings centrally in Azure for easier updates.
Config File - azure-pipelines.yml
azure-pipelines.yml
trigger:
- main

variables:
  - name: DATABASE_URL
    value: "Server=tcp:myserver.database.windows.net,1433;Initial Catalog=mydb;User ID=myuser;Password=MyP@ssw0rd;"
  - name: API_KEY
    value: "12345-abcde-67890-fghij"

jobs:
- job: BuildAndDeploy
  pool:
    vmImage: 'ubuntu-latest'
  steps:
  - script: |
      echo "Using database URL: $(DATABASE_URL)"
      echo "Using API key: $(API_KEY)"
    displayName: 'Show environment variables'

This Azure Pipelines YAML file defines two environment variables: DATABASE_URL and API_KEY. These variables store connection strings and keys outside the app code.

The variables section sets these values centrally.

In the steps, the script prints these variables to show how the app or pipeline can access them during build or deployment.

Commands
This command sets environment variables DATABASE_URL and API_KEY for the Azure Web App named 'my-app'. It stores these settings securely so the app can use them at runtime.
Terminal
az webapp config appsettings set --name my-app --resource-group my-resource-group --settings DATABASE_URL="Server=tcp:myserver.database.windows.net,1433;Initial Catalog=mydb;User ID=myuser;Password=MyP@ssw0rd;" API_KEY="12345-abcde-67890-fghij"
Expected OutputExpected
{"id":"/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/my-resource-group/providers/Microsoft.Web/sites/my-app/config/appsettings","name":"appsettings","type":"Microsoft.Web/sites/config","location":"East US","properties":{"DATABASE_URL":"Server=tcp:myserver.database.windows.net,1433;Initial Catalog=mydb;User ID=myuser;Password=MyP@ssw0rd;","API_KEY":"12345-abcde-67890-fghij"}}
→
--name - Specifies the name of the Azure Web App
→
--resource-group - Specifies the resource group containing the Web App
→
--settings - Defines the environment variables to set
This command lists all environment variables currently set for the Azure Web App 'my-app'. It helps verify that the variables were set correctly.
Terminal
az webapp config appsettings list --name my-app --resource-group my-resource-group
Expected OutputExpected
[{"name":"DATABASE_URL","value":"Server=tcp:myserver.database.windows.net,1433;Initial Catalog=mydb;User ID=myuser;Password=MyP@ssw0rd;"},{"name":"API_KEY","value":"12345-abcde-67890-fghij"}]
→
--name - Specifies the name of the Azure Web App
→
--resource-group - Specifies the resource group containing the Web App
This command restarts the Azure Web App 'my-app' to apply any changes made to environment variables or configuration.
Terminal
az webapp restart --name my-app --resource-group my-resource-group
Expected OutputExpected
No output (command runs silently)
→
--name - Specifies the name of the Azure Web App
→
--resource-group - Specifies the resource group containing the Web App
Key Concept

If you remember nothing else from this pattern, remember: environment variables let you change app settings safely without touching the app code.

Common Mistakes
Setting environment variables with incorrect syntax or missing quotes around values with special characters.
The command fails or the app reads wrong values, causing errors or security leaks.
Always wrap values containing special characters or spaces in double quotes when setting environment variables.
Not restarting the Azure Web App after changing environment variables.
The app continues running with old settings and does not pick up the new variables.
Run 'az webapp restart' after updating environment variables to apply changes.
Hardcoding sensitive information like passwords directly in app code instead of using environment variables.
This exposes secrets in code repositories and makes updates difficult and risky.
Use environment variables or Azure Key Vault to store secrets outside the app code.
Summary
Use 'az webapp config appsettings set' to add or update environment variables for your Azure Web App.
Verify environment variables with 'az webapp config appsettings list' to ensure they are set correctly.
Restart the app with 'az webapp restart' to apply any changes to environment variables.

Practice

(1/5)
1. What is the main purpose of using environment variables in Azure web apps?
easy
A. To write application logic inside the environment
B. To separate configuration settings from the application code
C. To store large files for the application
D. To replace the need for a database

Solution

  1. Step 1: Understand environment variables role

    Environment variables hold configuration data outside the code, making apps flexible and secure.
  2. Step 2: Identify correct purpose in Azure context

    Azure web apps use environment variables to keep settings separate from code, allowing easy updates without code changes.
  3. Final Answer:

    To separate configuration settings from the application code -> Option B
  4. Quick Check:

    Environment variables separate config from code [OK]
Hint: Think: config outside code for easy updates [OK]
Common Mistakes:
  • Confusing environment variables with code logic
  • Using environment variables to store large files
  • Assuming environment variables replace databases
2. Which Azure CLI command correctly sets an environment variable named API_KEY with value 12345 for a web app called myapp?
easy
A. az webapp config appsettings set --name myapp --resource-group mygroup --settings API_KEY=12345
B. az webapp set env --app myapp --key API_KEY --value 12345
C. az appservice env set --app myapp --name API_KEY --value 12345
D. az webapp config set --app myapp --env API_KEY=12345

Solution

  1. Step 1: Recall Azure CLI syntax for setting app settings

    The correct command uses az webapp config appsettings set with --name, --resource-group, and --settings.
  2. Step 2: Match command to given options

    az webapp config appsettings set --name myapp --resource-group mygroup --settings API_KEY=12345 matches the correct syntax exactly; others use incorrect commands or flags.
  3. Final Answer:

    az webapp config appsettings set --name myapp --resource-group mygroup --settings API_KEY=12345 -> Option A
  4. Quick Check:

    Use az webapp config appsettings set with correct flags [OK]
Hint: Remember: 'az webapp config appsettings set' sets env vars [OK]
Common Mistakes:
  • Using wrong Azure CLI commands or flags
  • Omitting resource group parameter
  • Confusing appsettings with environment commands
3. Given this Azure web app environment variable setup:
API_URL=https://api.example.com
What will the following Python code print?
import os
print(os.getenv('API_URL'))
medium
A. os.getenv('API_URL')
B. API_URL
C. None
D. https://api.example.com

Solution

  1. Step 1: Understand os.getenv behavior

    os.getenv('API_URL') fetches the value of environment variable 'API_URL' if set.
  2. Step 2: Match environment variable value

    The environment variable 'API_URL' is set to 'https://api.example.com', so the print outputs this string.
  3. Final Answer:

    https://api.example.com -> Option D
  4. Quick Check:

    os.getenv returns env var value [OK]
Hint: os.getenv returns the variable's value, not the name [OK]
Common Mistakes:
  • Expecting the variable name instead of its value
  • Assuming None if variable is set
  • Confusing function call with string output
4. You tried to update an environment variable in Azure CLI but the app still uses the old value. What is the most likely cause?
medium
A. Azure CLI does not support environment variable updates
B. You used the wrong variable name in the code
C. You forgot to restart the web app after updating the variable
D. Environment variables cannot be updated once set

Solution

  1. Step 1: Understand environment variable update behavior

    After updating environment variables, Azure web apps often require a restart to apply changes.
  2. Step 2: Identify common mistake

    Not restarting the app causes it to keep using old cached environment values.
  3. Final Answer:

    You forgot to restart the web app after updating the variable -> Option C
  4. Quick Check:

    Restart app to apply env var changes [OK]
Hint: Restart app after env var changes to apply them [OK]
Common Mistakes:
  • Assuming variables update instantly without restart
  • Confusing variable name errors with update issues
  • Thinking Azure CLI cannot update variables
5. You want to securely store a database password as an environment variable in Azure App Service. Which approach is best practice?
hard
A. Use Azure Key Vault and reference the secret in the app settings
B. Store the password directly in the app settings as plain text
C. Hardcode the password inside your application code
D. Send the password as a query parameter in URLs

Solution

  1. Step 1: Identify secure storage options

    Azure Key Vault is designed to securely store secrets like passwords and keys.
  2. Step 2: Understand integration with app settings

    You can reference Key Vault secrets in Azure App Service app settings, avoiding plain text storage.
  3. Step 3: Evaluate other options

    Storing passwords in plain text, code, or URLs exposes security risks and is not recommended.
  4. Final Answer:

    Use Azure Key Vault and reference the secret in the app settings -> Option A
  5. Quick Check:

    Use Key Vault for secure secret storage [OK]
Hint: Always use Key Vault for sensitive secrets [OK]
Common Mistakes:
  • Storing passwords in plain text app settings
  • Hardcoding secrets in code
  • Exposing secrets in URLs