Skip to main content

Managing secrets and secure access in Azure applications

Example of managing the secrets and permissions via services and features like KeyVault, AD Managed Identity, AD RBAC

This example lives in the pulumi/examples repository. Check out just this directory to use it:

Get started with this example
git clone --filter=blob:none --sparse https://github.com/pulumi/examples pulumi-examples
git -C pulumi-examples sparse-checkout set classic-azure-ts-msi-keyvault-rbac
cd pulumi-examples/classic-azure-ts-msi-keyvault-rbac

Managed identities for Azure resources provides Azure services with an automatically managed identity in Azure Active Directory (Azure AD).

This example demonstrates using a managed identity with Azure App Service to access Azure KeyVault, Azure Storage, and Azure SQL Database without passwords or secrets.

The application consists of several parts:

  • An ASP.NET Application which reads data from a SQL Database and from a file in Blob Storage
  • App Service which hosts the application. The application binaries are placed in Blob Storage, with the Blob URL placed as a secret in Azure Key Vault
  • App Service has a Managed Identity enabled
  • The identity is granted access to the SQL Server, Blob Storage, and Key Vault
  • No secret information is placed in App Service configuration: all access rights are derived from Active Directory

Prerequisites#

  1. Install Pulumi
  2. Configure Azure credentials
  3. Install Node.js

Deploying the example#

  1. Create a new stack:

    Terminal window
    pulumi stack init dev
  2. Log in to the Azure CLI (you will be prompted to do this during deployment if you forget this step):

    Terminal window
    az login
  3. Build and publish the ASP.NET Core project:

    Terminal window
    dotnet publish webapp
  4. Configure the target Azure environment:

    Terminal window
    pulumi config set azure:location <location>
    pulumi config set azure:subscriptionId <YOUR_SUBSCRIPTION_ID>
  5. Install dependencies:

    Terminal window
    npm install
  6. Deploy the stack:

    Terminal window
    pulumi up
    Previewing changes:
    ...
    Performing changes:
    ...
    info: 15 changes performed:
    + 15 resources created
    Update duration: 4m16s
  7. Check the deployed website endpoint:

    Terminal window
    pulumi stack output endpoint
    curl "$(pulumi stack output endpoint)"
    https://app129968b8.azurewebsites.net/
    Hello 311378b3-16b7-4889-a8d7-2eb77478beba@50f73f6a-e8e3-46b6-969c-bf026712a650! Here is your...

Cleaning up#

Once you are done, you can destroy all of the resources, and the stack:

Terminal window
pulumi destroy
pulumi stack rm

Related

The infrastructure as code platform for any cloud.