Microsoft Certified: DevOps Engineer ExpertDesign and implement source controlMedium
A development team is using Azure DevOps and wants to implement a consistent and secure way to manage secrets (e.g., API keys, database connection strings) that are used by their build pipelines. These secrets should not be hardcoded in YAML files and should be accessible only to authorized pipelines. Which Azure DevOps feature is best suited for this requirement?
- AVariable groups linked to Azure Key Vault
- BPipeline variables
- CBuild output variables
- DSecured files library
Show answer & explanationAnswer & explanation
Correct answer: A. Variable groups linked to Azure Key Vault
Variable groups linked to Azure Key Vault provide a secure and centralized way to manage secrets. Secrets stored in Key Vault are retrieved at runtime by authorized pipelines, preventing them from being exposed in source control or pipeline definitions.
Why the other options are wrong
- B. Pipeline variables can be marked as secret, but they are defined directly in the pipeline, which isn't as centralized or secure as Key Vault integration.
- C. Build output variables are used to pass values between tasks within a pipeline, not for securely storing and managing secrets.
- D. Secured files are for files (e.g., certificates), not individual secrets like API keys.
Azure DevOps Variable Groups with Key Vault
A feature in Azure DevOps that allows linking a variable group to an Azure Key Vault, enabling pipelines to securely access secrets stored in Key Vault at runtime.
- Secrets are never exposed in YAML or logs (when correctly handled).
- Provides centralized secret management.
- Requires appropriate permissions on Key Vault for the service connection.
Memory trick: Vault your variables for pipeline security.