Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium
A DevOps team is setting up a CI/CD pipeline for an application that handles sensitive customer data. They need to ensure that the secrets (e.g., database connection strings, API keys) used by the application in different environments (Development, Staging, Production) are securely stored and injected into the pipeline without being exposed in plain text. Which combination of Azure services should they use?
- AAzure Key Vault and Azure Pipelines Variable Groups
- BAzure Cosmos DB and Azure Policy
- CAzure Storage Accounts and Azure DevOps Variable Groups
- DGitHub Secrets and Azure App Configuration
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Key Vault and Azure Pipelines Variable Groups
Azure Key Vault is designed for securely storing and managing secrets, certificates, and encryption keys. Azure Pipelines Variable Groups can link directly to Key Vault secrets, allowing them to be securely injected into CI/CD pipelines without being exposed in plain text. This combination provides robust secret management for DevOps.
Why the other options are wrong
- B. Azure Cosmos DB is a NoSQL database. Azure Policy enforces compliance. Neither is designed for secure secret storage and injection into pipelines.
- C. Azure Storage Accounts are for general data storage, not secure secret management. Variable Groups alone in Azure DevOps are not as secure as Key Vault for storing sensitive production secrets.
- D. GitHub Secrets are for GitHub Actions, not directly integrated with Azure Pipelines for Key Vault access. Azure App Configuration is for application settings, not primary secret storage for pipelines.
Secure Secret Management in Azure DevOps
The practice of securely storing and retrieving sensitive information (secrets) required by applications and pipelines, typically using Azure Key Vault integrated with Azure Pipelines.
- Prevents exposure of secrets in code or logs.
- Centralizes secret management.
- Enables rotation and access control for secrets.
Memory trick: Key Vault 'Holds the Keys' for Pipelines to 'Unlock Safely'.