Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium

A DevOps team is deploying a highly sensitive application to Azure. The application requires access to various secrets (e.g., API keys, database connection strings) during deployment. These secrets must be securely stored, accessed, and rotated. The team wants to integrate Azure Key Vault with their Azure DevOps release pipelines to retrieve these secrets during deployment without hardcoding them. How should the team configure the release pipeline to achieve this securely?

  1. AUse a Service Connection to Azure Key Vault and link a Variable Group to it.
  2. BUpload secrets as secure files to the pipeline and reference them.
  3. CEmbed a PowerShell script in the pipeline to fetch secrets using Azure CLI.
  4. DStore secrets directly in pipeline variables and mark them as secret.
Show answer & explanation

Correct answer: A. Use a Service Connection to Azure Key Vault and link a Variable Group to it.

The most secure and recommended way to integrate Azure Key Vault with Azure DevOps is to create an Azure Resource Manager service connection to the Key Vault and then link a variable group to this service connection. This allows secrets from Key Vault to be injected as variables into the pipeline at runtime.

Why the other options are wrong

  • B. Secure files are for binary files or certificates, not typically for plain-text secrets like API keys, and don't offer the same rotation and access control benefits as Key Vault.
  • C. While possible, embedding custom scripts to fetch secrets is less secure, harder to maintain, and bypasses the native, integrated features for Key Vault.
  • D. Storing secrets directly in pipeline variables, even if marked secret, is less secure than Key Vault, as they are still managed within Azure DevOps itself.

Azure Key Vault Integration (Azure DevOps)

Integrating Azure Key Vault with Azure DevOps allows pipelines to securely retrieve secrets, keys, and certificates stored in Key Vault, preventing sensitive information from being hardcoded or exposed in pipeline definitions.

  • Uses Service Connections to authenticate with Key Vault.
  • Secrets are exposed as pipeline variables at runtime.
  • Enhances security, compliance, and secret management practices.

Memory trick: Key Vault unlocks secrets safely via service connections.

More Design and implement pipelines questions