Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium
A DevOps team is setting up a new release pipeline for a web application that will be deployed to an Azure App Service. The application uses a database connection string and an API key that are considered highly sensitive. These secrets must not be stored directly in the pipeline definition or source control. How should the team manage these secrets within the Azure DevOps release pipeline?
- AEncrypt the secrets and commit them to the Git repository, then decrypt them during deployment.
- BPass the secrets as command-line arguments to the deployment script.
- CStore the secrets in Azure Key Vault and link it to the Azure DevOps variable group, then reference the variables in the pipeline.
- DStore the secrets as pipeline variables and mark them as 'secret'.
Show answer & explanationAnswer & explanation
Correct answer: C. Store the secrets in Azure Key Vault and link it to the Azure DevOps variable group, then reference the variables in the pipeline.
Storing sensitive information in Azure Key Vault is the recommended secure practice. Azure DevOps can then link to Key Vault secrets via variable groups, allowing these secrets to be consumed in pipelines without being exposed in plain text in source control or the pipeline definition.
Why the other options are wrong
- A. Committing encrypted secrets to Git is still a risk, as the encryption key could be compromised, and it's not the best practice for secret management.
- B. Passing secrets as command-line arguments exposes them in process lists and potentially logs, which is a major security risk.
- D. While marking pipeline variables as 'secret' hides them in logs, they are still stored within Azure DevOps and not in a dedicated secret management service like Key Vault, making it less secure for highly sensitive data.
Azure Key Vault Integration (Azure DevOps)
The process of securely retrieving secrets, keys, and certificates from Azure Key Vault and making them available for use in Azure DevOps pipelines.
- Prevents secrets from being stored directly in source control or pipeline definitions.
- Enhances security by centralizing secret management.
- Supports rotation and access control for secrets.
Memory trick: Key Vault holds the keys, pipelines unlock them.