Managing Secrets and Secure Access in Azure Applications
Example of managing the secrets and permissions via services and features like KeyVault, AD Managed Identity, AD RBAC
This example lives in the pulumi/examples repository. Check out just this directory to use it:
git clone --filter=blob:none --sparse https://github.com/pulumi/examples pulumi-examplesgit -C pulumi-examples sparse-checkout set classic-azure-cs-msi-keyvault-rbaccd pulumi-examples/classic-azure-cs-msi-keyvault-rbacManaged identities for Azure resources provides Azure services with an automatically managed identity in Azure Active Directory (Azure AD).
This example demonstrates using a managed identity with Azure App Service to access Azure KeyVault, Azure Storage, and Azure SQL Database without passwords or secrets.
The application consists of several parts:
- An ASP.NET Application which reads data from a SQL Database and from a file in Blob Storage
- App Service which host the application. The application binaries are placed in Blob Storage, with Blob Url placed as a secret in Azure Key Vault
- App Service has a Managed Identity enabled
- The identify is granted access to the SQL Server, Blob Storage, and Key Vault
- No secret information is placed in App Service configuration: all access rights are derived from Active Directory
Deploying the App#
To deploy your infrastructure, follow the below steps.
Prerequisites#
Steps#
-
Create a new stack:
Terminal window pulumi stack init dev -
Login to Azure CLI (you will be prompted to do this during deployment if you forget this step):
Terminal window az login -
Build and publish the ASP.NET Core project:
Terminal window dotnet publish webapp -
Set an appropriate Azure location like:
Terminal window pulumi config set azure:location westuspulumi config set azure:subscriptionId <YOUR_SUBSCRIPTION_ID> -
Run
pulumi upto preview and deploy changes:Terminal window pulumi upPreviewing changes:...Performing changes:...info: 15 changes performed:+ 15 resources createdUpdate duration: 4m16s -
Check the deployed website endpoint:
Terminal window pulumi stack output Endpointhttps://app129968b8.azurewebsites.net/curl "$(pulumi stack output Endpoint)"Hello 311378b3-16b7-4889-a8d7-2eb77478beba@50f73f6a-e8e3-46b6-969c-bf026712a650! Here is your... -
From there, feel free to experiment. Simply making edits and running
pulumi upwill incrementally update your stack. -
Once you’ve finished experimenting, tear down your stack’s resources by destroying and removing it:
Terminal window pulumi destroy --yespulumi stack rm --yes