Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Storing secrets
📖 Scenario: You are working on a cloud project where you need to securely store sensitive information like passwords or API keys. Instead of keeping these secrets in your code, you will use Azure Key Vault, a service designed to hold secrets safely.
🎯 Goal: Create an Azure Key Vault resource, add a secret to it, and configure access policies to allow an application to retrieve the secret securely.
📋 What You'll Learn
Create an Azure Key Vault resource with a specific name and location
Add a secret with a given name and value to the Key Vault
Set an access policy to allow a specific principal to get secrets
💡 Why This Matters
🌍 Real World
Storing secrets securely is essential in cloud projects to protect sensitive data like passwords and API keys from exposure.
💼 Career
Cloud engineers and developers often use Azure Key Vault to manage secrets safely and control access in real-world applications.
Progress0 / 4 steps
1
Create Azure Key Vault resource
Create an Azure Key Vault resource named myKeyVault in the eastus region using the Azure CLI command az keyvault create.
Azure
Hint
Use az keyvault create --name myKeyVault --resource-group myResourceGroup --location eastus to create the Key Vault.
2
Add a secret to the Key Vault
Add a secret named DbPassword with the value MyS3cretPass! to the Key Vault myKeyVault using the Azure CLI command az keyvault secret set.
Azure
Hint
Use az keyvault secret set --vault-name myKeyVault --name DbPassword --value MyS3cretPass! to add the secret.
3
Set access policy for secret retrieval
Set an access policy on myKeyVault to allow the principal with object ID 12345678-1234-1234-1234-123456789abc to get secrets using the Azure CLI command az keyvault set-policy.
Azure
Hint
Use az keyvault set-policy --name myKeyVault --object-id 12345678-1234-1234-1234-123456789abc --secret-permissions get to set the access policy.
4
Verify secret retrieval configuration
Verify that the secret DbPassword can be retrieved from myKeyVault by the principal with object ID 12345678-1234-1234-1234-123456789abc using the Azure CLI command az keyvault secret show.
Azure
Hint
Use az keyvault secret show --vault-name myKeyVault --name DbPassword to verify the secret.
Practice
(1/5)
1. What is the main purpose of using Azure Key Vault to store secrets?
easy
A. To keep sensitive information safe and separate from application code
B. To speed up application performance by caching data
C. To store large files like videos and images
D. To create virtual machines automatically
Solution
Step 1: Understand what secrets are
Secrets are sensitive data like passwords or keys that should be protected.
Step 2: Identify Azure Key Vault's role
Azure Key Vault securely stores and manages these secrets separately from code.
Final Answer:
To keep sensitive information safe and separate from application code -> Option A
2. Which Azure CLI command correctly adds a secret named MySecret with value abc123 to a Key Vault named MyVault?
easy
A. az keyvault secret add --vault MyVault --secret-name MySecret --secret-value abc123
B. az keyvault secret set --vault-name MyVault --name MySecret --value abc123
C. az keyvault secret create --vault-name MyVault --secret MySecret --value abc123
D. az keyvault secret upload --vault MyVault --name MySecret --value abc123
Solution
Step 1: Recall the correct Azure CLI command for adding secrets
The correct command is az keyvault secret set with parameters for vault name, secret name, and value.
Step 2: Match parameters with the command
az keyvault secret set --vault-name MyVault --name MySecret --value abc123 uses the correct command and parameters: --vault-name, --name, and --value.
Final Answer:
az keyvault secret set --vault-name MyVault --name MySecret --value abc123 -> Option B
Quick Check:
Use az keyvault secret set to add secrets [OK]
Hint: Add secrets with 'az keyvault secret set' command [OK]
Common Mistakes:
Using incorrect command verbs like add or create
Wrong parameter names like --secret-name instead of --name
Confusing upload with set command
3. Given this Azure CLI command:
az keyvault secret show --vault-name MyVault --name ApiKey
What will this command do?
medium
A. It retrieves the value of the secret named ApiKey from MyVault
B. It deletes the secret named ApiKey from MyVault
C. It lists all secrets stored in MyVault
D. It creates a new secret named ApiKey in MyVault
Solution
Step 1: Understand the command structure
The command uses az keyvault secret show which is for retrieving a secret's value.
Step 2: Identify the parameters
--vault-name MyVault specifies the vault, and --name ApiKey specifies the secret to retrieve.
Final Answer:
It retrieves the value of the secret named ApiKey from MyVault -> Option A
Quick Check:
secret show = retrieve secret [OK]
Hint: Use 'secret show' to get secret values [OK]
Common Mistakes:
Confusing show with delete or create commands
Thinking it lists all secrets
Mixing up secret names and vault names
4. You run this command:
az keyvault secret set --vault-name MyVault --name Password
But it fails with an error. What is the most likely cause?
medium
A. The secret name Password is invalid
B. The vault name MyVault does not exist
C. You forgot to provide the secret value with --value parameter
D. You need to use 'secret create' instead of 'secret set'
Solution
Step 1: Check the command parameters
The command is missing the --value parameter which is required to specify the secret's value.
Step 2: Consider other options
While vault existence and secret name validity matter, the error is most commonly due to missing the secret value.
Final Answer:
You forgot to provide the secret value with --value parameter -> Option C
Quick Check:
Missing --value causes failure [OK]
Hint: Always include --value when setting a secret [OK]
Common Mistakes:
Assuming 'secret create' is a valid command
Ignoring missing required parameters
Not verifying vault existence first
5. You want to securely store multiple environment variables as secrets in Azure Key Vault and access them in your app without exposing them in code. Which approach is best?
hard
A. Save the variables in a public GitHub repo and use environment variables locally
B. Store all variables in a single secret as a JSON string and parse it in your app
C. Hardcode the variables in your app and encrypt the app binary
D. Store each variable as a separate secret in Key Vault and configure your app to fetch them at runtime
Solution
Step 1: Understand secure secret storage best practices
Storing each secret separately allows fine-grained control and easier management.
Step 2: Evaluate options for app access
Fetching secrets at runtime keeps secrets out of code and source control, improving security.
Final Answer:
Store each variable as a separate secret in Key Vault and configure your app to fetch them at runtime -> Option D
Quick Check:
Separate secrets + runtime fetch = best practice [OK]
Hint: Use separate secrets and fetch at runtime for security [OK]