Skip to main content

Automate the rotation of a secret for resources that use one set of authentication credentials

Example of rotating secrets with one set of credentials

This example lives in the pulumi/examples repository. Check out just this directory to use it:

Get started with this example
git clone --filter=blob:none --sparse https://github.com/pulumi/examples pulumi-examples
git -C pulumi-examples sparse-checkout set azure-cs-credential-rotation-one-set
cd pulumi-examples/azure-cs-credential-rotation-one-set

Modeled after Microsoft ARM documentation

This example demonstrates using a managed identity with Azure App Service to access Azure KeyVault, Azure Storage, and Azure SQL Database without passwords or secrets.

The application consists of several parts:

  • A SQL Server to rotate credendials
  • A KeyVault that stores the credentials of the SQL Server
  • A KeyVault that is only accessible to the WebApp and Function (through Managed Identity)
  • An Azure Function that generates a new secret and sets it in SQL Server and Key Vault
  • An Azure WebApp that shows that the secret is changing and still accessible
  • An EventGrid subscription to receive SecretNearExpiry events from KeyVault and, in turn, call the Azure Function

IMPORTANT: For example purposes, new secrets are continually generated. Make sure to change the validityPeriod or destroy the stack when you are done.

Prerequisites#

  1. Install Pulumi
  2. Configure Azure credentials
  3. Install .NET

Deploying the example#

  1. Create a new stack:

    Terminal window
    pulumi stack init dev
  2. Login to Azure CLI (you will be prompted to do this during deployment if you forget this step):

    Terminal window
    az login
  3. Build and publish the ASP.NET Core project:

    Terminal window
    dotnet publish webapp
  4. Set the Azure region location to use:

    Terminal window
    pulumi config set azure-native:location westus2
  5. Run pulumi up to preview and deploy changes:

    Terminal window
    pulumi up
  6. Check the deployed website endpoint:

    Terminal window
    pulumi stack output WebAppEndpoint
    Start-Process "$(pulumi stack output WebAppEndpoint)"
    https://app129968b8.azurewebsites.net/
  7. From there, feel free to experiment. Simply making edits and running pulumi up will incrementally update your stack.

Cleaning up#

Once you’ve finished experimenting, tear down your stack’s resources by destroying and removing it:

Terminal window
pulumi destroy
pulumi stack rm

Related

The infrastructure as code platform for any cloud.