1. What is Azure Key Vault Integration?
Azure Key Vault integration allows Azure DevOps Pipelines to securely retrieve sensitive information from Azure Key Vault during build or deployment.
Azure Key Vault can store:
-
Database passwords and connection strings
-
API keys and access tokens
-
JWT signing secrets
-
Certificates and cryptographic keys
Instead of hardcoding these values in azure-pipelines.yml, we store them in Azure Key Vault and retrieve them securely when needed.
Main purpose: Protect application secrets and manage them centrally without exposing credentials in source code or pipeline configuration.
2. How does it work?
Azure Key Vault
|
| Stores:
| - DbPassword
| - ApiKey
| - JwtSecret
|
v
Azure Service Connection
|
| Authenticates Pipeline
v
Azure DevOps Pipeline
|
| AzureKeyVault@2 Task
v
Retrieve Required Secrets
|
v
Deploy ASP.NET Core Web API
|
v
Configure Application Securely
The Azure Service Connection provides an identity for authentication. Azure Key Vault permissions determine which secrets that identity can access.
There are two common integration methods:
-
AzureKeyVault@2 task: Retrieve secrets directly within a YAML pipeline.
-
Key Vault-linked Variable Group: Link a Variable Group to Azure Key Vault and use its secrets across pipelines.
3. Method 1 – Using AzureKeyVault@2 Task
This is a straightforward way to retrieve secrets directly in a YAML pipeline.
Step 1 – Create Azure Key Vault
In the Azure Portal:
-
Search for Key Vaults.
-
Click Create.
-
Select Subscription and Resource Group.
-
Enter a Key Vault name, for example
kv-employee-prod. -
Select a region and create the vault.
Step 2 – Add Secrets
Navigate to:
Azure Portal → Key Vault → Objects → Secrets → Generate/Import
Create the following example secrets:
|
Secret name |
Example value |
|---|---|
|
|
A secure database password |
|
|
An application API key |
|
|
A strong JWT signing secret |
The actual secret values remain stored in Key Vault.
Step 3 – Create an Azure Service Connection
Navigate to:
Azure DevOps → Project Settings → Service connections → New service connection
Choose:
-
Connection type: Azure Resource Manager
-
Authentication: Workload identity federation (recommended)
-
Azure subscription: The subscription containing Key Vault
-
Connection name:
Production-ServiceConnection
This service connection allows Azure Pipelines to authenticate to Azure without storing a long-lived client secret.
Step 4 – Grant Key Vault Access
Open your Key Vault in the Azure Portal.
For a vault using Azure RBAC:
-
Open Access control (IAM).
-
Click Add role assignment.
-
Select Key Vault Secrets User.
-
Assign the role to the identity used by your service connection.
-
Save the assignment.
For a vault using access policies, grant the identity Get and List secret permissions instead.
Also ensure the pipeline agent has network access to the vault.
Step 5 – Add AzureKeyVault@2 to YAML
trigger:
- main
pool:
vmImage: 'windows-latest'
steps:
- task: AzureKeyVault@2
displayName: 'Retrieve secrets from Key Vault'
inputs:
azureSubscription: 'Production-ServiceConnection'
KeyVaultName: 'kv-employee-prod'
SecretsFilter: 'DbPassword,ApiKey,JwtSecret'
RunAsPreJob: false
- task: PowerShell@2
displayName: 'Use secrets securely'
inputs:
targetType: 'inline'
script: |
Write-Host "Secrets are available to this task"
env:
DB_PASSWORD: $(DbPassword)
API_KEY: $(ApiKey)
JWT_SECRET: $(JwtSecret)
Important YAML properties
|
Property |
Purpose |
|---|---|
|
|
Name of the Azure service connection |
|
|
Azure Key Vault name |
|
|
Comma-separated secret names; |
|
|
If true, makes secrets available to all tasks in the job |
Once the task succeeds, the retrieved values become secret pipeline variables for subsequent tasks in that job. They should be explicitly mapped to environment variables when scripts need them.
4. Method 2 – Using Key Vault-linked Variable Groups
This method is useful when multiple pipelines need the same secrets.
Steps
-
Open Azure DevOps → Pipelines → Library.
-
Click + Variable group.
-
Enter the name
PROD-Secrets. -
Enable Link secrets from an Azure Key Vault as variables.
-
Select your Azure service connection.
-
Select
kv-employee-prod. -
Click Add and select the required secrets.
-
Save and authorize the Variable Group for the pipeline.
YAML Example
variables:
- group: PROD-Secrets
steps:
- task: PowerShell@2
inputs:
targetType: 'inline'
script: |
Write-Host "Production secrets are available"
env:
DB_PASSWORD: $(DbPassword)
API_KEY: $(ApiKey)
Important: Variable Groups map selected secret names rather than copying secret values into the group. Updated values of existing mapped secrets are retrieved at runtime. Newly added secret names must be mapped manually.
5. AzureKeyVault@2 vs Key Vault-linked Variable Group
|
Feature |
AzureKeyVault@2 |
Variable Group |
|---|---|---|
|
Secret retrieval |
Directly from a pipeline task |
Through a linked group |
|
Configuration |
YAML |
Azure DevOps Library |
|
Reusability |
Configure task where needed |
Shared across pipelines |
|
Secret selection |
|
Select secrets in Library |
|
Best suited for |
Explicit secret retrieval in a job |
Centralized shared secrets |
Both methods are valid. Choose based on your pipeline architecture and access-control requirements.
6. Real Project Example – ASP.NET Core Web API
Suppose you deploy an Employee Web API to four environments.
Azure DevOps CI Pipeline
|
v
Build ASP.NET Core Web API
|
v
Publish Artifact
|
v
DEV Deployment
→ DEV Key Vault
|
v
SIT Deployment
→ SIT Key Vault
|
v
UAT Deployment
→ UAT Key Vault
|
v
Production Approval
|
v
PROD Deployment
→ Production Key Vault
Each deployment stage uses a separate Key Vault or appropriately isolated secrets.
The application can receive its configuration through secure App Service settings or Key Vault references.
Important distinction: Retrieving a secret into Azure Pipelines does not automatically configure the deployed ASP.NET Core application. The deployment process must pass it securely to the application, or the application must access Key Vault directly through Managed Identity.
7. Common Issues and Troubleshooting
|
Error |
Possible cause |
Solution |
|---|---|---|
|
|
Missing Key Vault permissions |
Grant Secrets User or required access-policy permissions |
|
Secret not found |
Incorrect secret name |
Verify name and |
|
Service connection error |
Missing authorization |
Authorize the pipeline to use the connection |
|
Network access denied |
Key Vault firewall/private endpoint restrictions |
Configure permitted network access |
|
Variable is empty |
Secret unavailable or not mapped |
Check retrieval task, scope, and variable name |
For private Key Vaults, a self-hosted agent with appropriate private network connectivity is often necessary.
8. Important Interview Questions
Q1. How does Azure Pipelines authenticate to Azure Key Vault?
Through an Azure Resource Manager service connection, preferably using workload identity federation.
Q2. Which task retrieves secrets from Azure Key Vault?
AzureKeyVault@2.
Q3. Can multiple pipelines use the same Key Vault secrets?
Yes. Pipelines can access authorized secrets directly or through a Key Vault-linked Variable Group.
Q4. What happens when a secret is rotated in Azure Key Vault?
Subsequent pipeline runs can retrieve the latest enabled secret version. Already-running applications may need configuration refresh or restart depending on how they consume the secret.
Q5. How do you protect Production secrets?
Use separate Key Vaults, least-privilege RBAC, restricted service connections, pipeline permissions, and Production deployment approvals.
9. Interview-ready Answer
"In Azure DevOps, we integrate Azure Key Vault with Azure Pipelines using an Azure Resource Manager service connection.
First, we create a Key Vault and store sensitive information such as database passwords, connection strings, and API keys.
Next, we configure a service connection using workload identity federation and grant the required Key Vault permissions.
In our YAML pipeline, we use the AzureKeyVault@2 task to retrieve the required secrets securely. Alternatively, we can link Azure Key Vault to a Variable Group and share secrets across pipelines.
For DEV, SIT, UAT, and Production, we maintain separate secret configurations and restrict Production access.
This approach eliminates hardcoded secrets and improves security and maintainability."
Key takeaway: Azure Key Vault stores secrets, the Azure Service Connection authenticates the pipeline, and AzureKeyVault@2 or a linked Variable Group makes authorized secrets available during execution.