Automated secrets rotation in Azure Key Vault

  Рет қаралды 9,015

Azure Secrets Management

Azure Secrets Management

Күн бұрын

Automated secrets rotation in Azure Key Vault with Azure Functions.
Link to Part 2 for AAD App Clients secrets rotation: • Automated secrets rota...
Available rotation functions can be found in Azure serverless community library:
serverlesslibr...
Feel free to contribute and build your own rotation functions for other providers.

Пікірлер: 21
@16michellevalverde
@16michellevalverde Жыл бұрын
thanks for sharing this. Is it also applicable to auto rotation of SPN? also what will be best the runtime stack used for that?
@azuresecretsmanagement4926
@azuresecretsmanagement4926 Жыл бұрын
For Service Principal is Part 2. I created video here: kzbin.info/www/bejne/gH7NqHWeo6h0fc0
@armaans64
@armaans64 5 ай бұрын
@@azuresecretsmanagement4926 using this, is it possible to rotate multiple SP secret
@holivieri
@holivieri Жыл бұрын
Great video, do we need to change anything in the source code of apps that use that secret?
@azuresecretsmanagement4926
@azuresecretsmanagement4926 Жыл бұрын
All you need is to get latest in the app. There is nothing special. You can use SDK or platform with support for auto update. App Services(web app, function app) : Key Vault Reference feature AKS : Secrets CSI Driver VM : Can use App Configuration Service with Key Vault references
@arunprakash1101
@arunprakash1101 Жыл бұрын
How different are Azure workload identities from this?
@azuresecretsmanagement4926
@azuresecretsmanagement4926 Жыл бұрын
This solutions is to rotate credentials, which could include workload identities like service principal secrets.
@abhinanda8880
@abhinanda8880 3 жыл бұрын
Easy to understand and helpful. Thank you
@prashanth4899
@prashanth4899 Жыл бұрын
Hi abhinanda, do you know how to rotate the keys for azure open AI?
@abhinanda8880
@abhinanda8880 Жыл бұрын
@@prashanth4899 open Ai?
@prashanth4899
@prashanth4899 Жыл бұрын
@@abhinanda8880 Yes
@ashishkapoor3816
@ashishkapoor3816 2 жыл бұрын
This was the demo for rotation of secrets for services that uses two set of credentials like Storage Account/ Cache for Redis. Then there are services which uses one set of credentials like SQL server. Is there easy way to classify of all azure services?
@azuresecretsmanagement4926
@azuresecretsmanagement4926 Жыл бұрын
There is no difference in general pattern. SQL supports multiple credentials, so you will have user1/pass1,user2/pass2.
@prashanth4899
@prashanth4899 Жыл бұрын
Awesome Video. I wanted to auto Rotate the 2 access key of my azure Open AI service on every 1 hour schedule. Could you please guide me how can i acheive this.
@azuresecretsmanagement4926
@azuresecretsmanagement4926 Жыл бұрын
Key Vault does not scale to short-lived credentials. Also, with this frequency any issue will cause an outage. 1h frequency mostly for dynamic credentials/token based, regardless custom solution outside of Key Vault would be required.
@ramubhusal9398
@ramubhusal9398 3 жыл бұрын
Is there other way to achieve Auto Key/Secrets Rotation without using Azure Cache for Redis?
@azuresecretsmanagement4926
@azuresecretsmanagement4926 3 жыл бұрын
In this scenario we rotate Azure Cache for Redis Key and storing copy of it in Key Vault for application use. You can use provided in serverless community template to create your own rotation Function to rotate any password/key for any resource .
@swarupsamrat
@swarupsamrat 3 жыл бұрын
Hey!! What if in place of rotating keys for storage, I want to rotate the keys of event hub. How do i do it?
@azuresecretsmanagement4926
@azuresecretsmanagement4926 3 жыл бұрын
You can use that pattern to rotate any access key or password. I created template with instructions here: github.com/Azure/KeyVault-Secrets-Rotation-Template-PowerShell/blob/main/Project-Template-Instructions.md
@venkateshboda1473
@venkateshboda1473 2 жыл бұрын
excellent
Automated secrets rotation in Azure Key Vault (Part 2) - AAD App Client Secret
13:11
Azure Secrets Management
Рет қаралды 1,8 М.
Azure Key Vault RBAC and Policy Deep Dive
20:14
John Savill's Technical Training
Рет қаралды 14 М.
🕊️Valera🕊️
00:34
DO$HIK
Рет қаралды 6 МЛН
«Кім тапқыр?» бағдарламасы
00:16
Balapan TV
Рет қаралды 293 М.
小丑家的感情危机!#小丑#天使#家庭
00:15
家庭搞笑日记
Рет қаралды 30 МЛН
Ozoda - Lada ( Official Music Video 2024 )
06:07
Ozoda
Рет қаралды 29 МЛН
Using Azure Key Vault Key Rotation Policies
22:23
John Savill's Technical Training
Рет қаралды 11 М.
Secure your secrets with Azure Functions & KeyVault
9:32
Azure App Modernization
Рет қаралды 10 М.
Azure Key Vault Tutorial | Secure secrets, keys and certificates easily
18:43
Adam Marczak - Azure for Everyone
Рет қаралды 179 М.
Manage Kubernetes Secrets With External Secrets Operator (ESO)
12:05
DevOps Toolkit
Рет қаралды 26 М.
Integrate Azure functions with Azure KeyVault
13:06
GPS
Рет қаралды 17 М.
Private Endpoints and DNS in Azure
16:48
Travis Roberts
Рет қаралды 44 М.
Access Azure Key Vault with Managed Identity
9:12
A Cloud Master
Рет қаралды 9 М.
🕊️Valera🕊️
00:34
DO$HIK
Рет қаралды 6 МЛН