Bird
Raised Fist0
Azurecloud~5 mins

Storing secrets in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
When you build applications, you often need to keep passwords, keys, or tokens safe. Storing secrets securely means keeping them hidden and protected from unauthorized access. Azure Key Vault helps you store and manage these secrets safely in the cloud.
When your app needs to use a database password without exposing it in code.
When you want to share API keys securely between team members.
When you need to rotate or update credentials without changing your app code.
When you want to control who can access sensitive information in your cloud environment.
When you want to audit access to secrets for security compliance.
Config File - azure-keyvault-policy.json
azure-keyvault-policy.json
{
  "properties": {
    "accessPolicies": [
      {
        "tenantId": "00000000-0000-0000-0000-000000000000",
        "objectId": "11111111-1111-1111-1111-111111111111",
        "permissions": {
          "secrets": ["get", "list", "set", "delete"]
        }
      }
    ]
  }
}

This JSON file defines who can access the secrets in the Azure Key Vault. tenantId is your Azure Active Directory tenant, objectId is the user or app allowed to manage secrets, and permissions specify allowed actions like reading or writing secrets.

Commands
This command creates a new Azure Key Vault named 'myExampleVault' in the 'exampleResourceGroup' resource group located in East US. This vault will store your secrets securely.
Terminal
az keyvault create --name myExampleVault --resource-group exampleResourceGroup --location eastus
Expected OutputExpected
{ "id": "/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/resourceGroups/exampleResourceGroup/providers/Microsoft.KeyVault/vaults/myExampleVault", "location": "eastus", "name": "myExampleVault", "properties": { "vaultUri": "https://myExampleVault.vault.azure.net/" }, "resourceGroup": "exampleResourceGroup", "type": "Microsoft.KeyVault/vaults" }
→
--name - Sets the name of the Key Vault.
→
--resource-group - Specifies the Azure resource group.
→
--location - Sets the Azure region for the vault.
This command stores a secret named 'DbPassword' with the value 'S3cureP@ssw0rd' inside the 'myExampleVault' Key Vault. Your app can later retrieve this secret securely.
Terminal
az keyvault secret set --vault-name myExampleVault --name DbPassword --value "S3cureP@ssw0rd"
Expected OutputExpected
{ "id": "https://myExampleVault.vault.azure.net/secrets/DbPassword/xxxxxxxxxxxx", "attributes": { "enabled": true, "created": 1680000000, "updated": 1680000000 } }
→
--vault-name - Specifies which Key Vault to use.
→
--name - Names the secret.
→
--value - Sets the secret's value.
This command retrieves the secret named 'DbPassword' from the 'myExampleVault' Key Vault so you can verify it was stored correctly.
Terminal
az keyvault secret show --vault-name myExampleVault --name DbPassword
Expected OutputExpected
{ "id": "https://myExampleVault.vault.azure.net/secrets/DbPassword/xxxxxxxxxxxx", "attributes": { "enabled": true, "created": 1680000000, "updated": 1680000000 } }
→
--vault-name - Specifies which Key Vault to query.
→
--name - Names the secret to retrieve.
This command deletes the secret named 'DbPassword' from the Key Vault when it is no longer needed or must be rotated.
Terminal
az keyvault secret delete --vault-name myExampleVault --name DbPassword
Expected OutputExpected
{ "recoveryId": "https://myExampleVault.vault.azure.net/deletedsecrets/DbPassword", "deletedDate": 1680000000, "scheduledPurgeDate": 1682592000, "id": "https://myExampleVault.vault.azure.net/secrets/DbPassword/xxxxxxxxxxxx", "attributes": { "enabled": false } }
→
--vault-name - Specifies which Key Vault to modify.
→
--name - Names the secret to delete.
Key Concept

If you remember nothing else from this pattern, remember: Azure Key Vault keeps your secrets safe and separate from your app code, so you never expose sensitive data directly.

Common Mistakes
Storing secrets directly in application code or configuration files.
This exposes sensitive data to anyone who can see the code or config, risking security breaches.
Use Azure Key Vault to store secrets and retrieve them securely at runtime.
Not setting proper access policies for the Key Vault.
Without correct permissions, your app or users cannot access the secrets, causing failures.
Define access policies with correct tenant and object IDs to allow authorized access.
Using weak or guessable secret values.
Weak secrets can be easily cracked, defeating the purpose of secure storage.
Use strong, complex secret values and rotate them regularly.
Summary
Create an Azure Key Vault to store secrets securely.
Add secrets to the vault using the Azure CLI.
Retrieve secrets safely when your app needs them.
Delete or rotate secrets to maintain security.

Practice

(1/5)
1. What is the main purpose of using Azure Key Vault to store secrets?
easy
A. To keep sensitive information safe and separate from application code
B. To speed up application performance by caching data
C. To store large files like videos and images
D. To create virtual machines automatically

Solution

  1. Step 1: Understand what secrets are

    Secrets are sensitive data like passwords or keys that should be protected.
  2. Step 2: Identify Azure Key Vault's role

    Azure Key Vault securely stores and manages these secrets separately from code.
  3. Final Answer:

    To keep sensitive information safe and separate from application code -> Option A
  4. Quick Check:

    Azure Key Vault = Secure secret storage [OK]
Hint: Secrets = sensitive info; Key Vault keeps them safe [OK]
Common Mistakes:
  • Thinking Key Vault speeds up app performance
  • Confusing secrets with large file storage
  • Assuming Key Vault creates virtual machines
2. Which Azure CLI command correctly adds a secret named MySecret with value abc123 to a Key Vault named MyVault?
easy
A. az keyvault secret add --vault MyVault --secret-name MySecret --secret-value abc123
B. az keyvault secret set --vault-name MyVault --name MySecret --value abc123
C. az keyvault secret create --vault-name MyVault --secret MySecret --value abc123
D. az keyvault secret upload --vault MyVault --name MySecret --value abc123

Solution

  1. Step 1: Recall the correct Azure CLI command for adding secrets

    The correct command is az keyvault secret set with parameters for vault name, secret name, and value.
  2. Step 2: Match parameters with the command

    az keyvault secret set --vault-name MyVault --name MySecret --value abc123 uses the correct command and parameters: --vault-name, --name, and --value.
  3. Final Answer:

    az keyvault secret set --vault-name MyVault --name MySecret --value abc123 -> Option B
  4. Quick Check:

    Use az keyvault secret set to add secrets [OK]
Hint: Add secrets with 'az keyvault secret set' command [OK]
Common Mistakes:
  • Using incorrect command verbs like add or create
  • Wrong parameter names like --secret-name instead of --name
  • Confusing upload with set command
3. Given this Azure CLI command:
az keyvault secret show --vault-name MyVault --name ApiKey

What will this command do?
medium
A. It retrieves the value of the secret named ApiKey from MyVault
B. It deletes the secret named ApiKey from MyVault
C. It lists all secrets stored in MyVault
D. It creates a new secret named ApiKey in MyVault

Solution

  1. Step 1: Understand the command structure

    The command uses az keyvault secret show which is for retrieving a secret's value.
  2. Step 2: Identify the parameters

    --vault-name MyVault specifies the vault, and --name ApiKey specifies the secret to retrieve.
  3. Final Answer:

    It retrieves the value of the secret named ApiKey from MyVault -> Option A
  4. Quick Check:

    secret show = retrieve secret [OK]
Hint: Use 'secret show' to get secret values [OK]
Common Mistakes:
  • Confusing show with delete or create commands
  • Thinking it lists all secrets
  • Mixing up secret names and vault names
4. You run this command:
az keyvault secret set --vault-name MyVault --name Password

But it fails with an error. What is the most likely cause?
medium
A. The secret name Password is invalid
B. The vault name MyVault does not exist
C. You forgot to provide the secret value with --value parameter
D. You need to use 'secret create' instead of 'secret set'

Solution

  1. Step 1: Check the command parameters

    The command is missing the --value parameter which is required to specify the secret's value.
  2. Step 2: Consider other options

    While vault existence and secret name validity matter, the error is most commonly due to missing the secret value.
  3. Final Answer:

    You forgot to provide the secret value with --value parameter -> Option C
  4. Quick Check:

    Missing --value causes failure [OK]
Hint: Always include --value when setting a secret [OK]
Common Mistakes:
  • Assuming 'secret create' is a valid command
  • Ignoring missing required parameters
  • Not verifying vault existence first
5. You want to securely store multiple environment variables as secrets in Azure Key Vault and access them in your app without exposing them in code. Which approach is best?
hard
A. Save the variables in a public GitHub repo and use environment variables locally
B. Store all variables in a single secret as a JSON string and parse it in your app
C. Hardcode the variables in your app and encrypt the app binary
D. Store each variable as a separate secret in Key Vault and configure your app to fetch them at runtime

Solution

  1. Step 1: Understand secure secret storage best practices

    Storing each secret separately allows fine-grained control and easier management.
  2. Step 2: Evaluate options for app access

    Fetching secrets at runtime keeps secrets out of code and source control, improving security.
  3. Final Answer:

    Store each variable as a separate secret in Key Vault and configure your app to fetch them at runtime -> Option D
  4. Quick Check:

    Separate secrets + runtime fetch = best practice [OK]
Hint: Use separate secrets and fetch at runtime for security [OK]
Common Mistakes:
  • Putting all secrets in one JSON string secret
  • Hardcoding secrets in app code
  • Exposing secrets in public repositories