Microsoft Certified: DevOps Engineer ExpertDesign and implement source controlHard
A development team uses Azure DevOps for their source control and build pipelines. They maintain sensitive configuration values, such as API keys and database connection strings, that are required by their build and release pipelines. These values must be stored securely and be accessible to pipelines without being hardcoded in YAML files. The team also wants to manage these secrets centrally and integrate with Azure Key Vault for enhanced security. Which Azure DevOps feature should they use?
- APipeline variables
- BService connections
- CVariable groups linked to Azure Key Vault
- DSecure files
Show answer & explanationAnswer & explanation
Correct answer: C. Variable groups linked to Azure Key Vault
Variable groups in Azure DevOps allow you to store values that can be shared across multiple pipelines. When linked to Azure Key Vault, these variable groups can securely retrieve secrets directly from Key Vault at runtime. This provides central, secure management of sensitive configuration values, preventing them from being hardcoded and leveraging Key Vault's security features.
Why the other options are wrong
- A. Pipeline variables can be marked as secret, but they are defined within a single pipeline or pipeline group and don't offer central management or direct integration with Key Vault.
- B. Service connections are for establishing connections to external services for authentication or resource access, not for storing and managing pipeline secrets themselves.
- D. Secure files are for storing entire files securely (e.g., certificates), not individual sensitive key-value pairs.
Azure Pipelines Variable Groups with Key Vault
A feature in Azure DevOps that allows you to store reusable sets of variables and securely link them to secrets stored in Azure Key Vault, making them accessible to pipelines at runtime.
- Centralized management of secrets and configuration values.
- Secrets are retrieved from Key Vault at runtime, not stored in Azure DevOps.
- Enhances security by leveraging Key Vault's access control and auditing.
- Variables can be shared across multiple pipelines.
Memory trick: Variable groups with Key Vault unlock secrets for pipelines.