Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium

A company uses Azure DevOps for its CI/CD pipelines. They have a web application deployed to Azure App Service. The development team has implemented a new feature that requires a specific environment variable to be set in the production slot, but not in the staging slot. This variable contains sensitive information. How should the team configure the release pipeline to manage this environment variable securely and ensure it's only applied to the production slot?

  1. AStore the variable in Azure Key Vault and reference it in the App Service application settings for the production slot only, marking it as a slot setting.
  2. BHardcode the variable in the application's configuration file and deploy different builds for staging and production.
  3. CDefine the variable directly in the App Service application settings for both slots and manually remove it from staging.
  4. DAdd the variable as a pipeline variable in Azure DevOps, scoped to the production stage, and use it in the App Service Deploy task.
Show answer & explanation

Correct answer: A. Store the variable in Azure Key Vault and reference it in the App Service application settings for the production slot only, marking it as a slot setting.

Storing sensitive information in Azure Key Vault provides a secure way to manage secrets. By referencing this secret in the App Service application settings for the production slot and marking it as a slot setting, it ensures the variable is specific to that slot and not swapped with other slots during a swap operation, maintaining security and correct configuration.

Why the other options are wrong

  • B. Hardcoding sensitive information is highly insecure and requires separate builds for different environments, which is not a best practice.
  • C. Manually managing sensitive variables is error-prone and insecure. It also doesn't prevent swapping.
  • D. Pipeline variables are not designed for secrets that need to persist securely in the App Service itself and be slot-specific after deployment. Key Vault is the appropriate solution for secrets.

Azure App Service Slot Settings

Configuration settings (like connection strings or app settings) that 'stick' to a specific deployment slot (e.g., production, staging) and are not swapped when slot content is swapped.

  • Ensures environment-specific configurations remain with their respective slots.
  • Critical for managing sensitive or environment-dependent settings.
  • Prevents accidental exposure or misconfiguration during slot swaps.

Memory trick: Key Vault locks secrets, slot settings keeps them in their place.

More Design and implement pipelines questions