Key Vault references in App Service and Functions
Keep secrets in Key Vault without changing a line of code. App settings can point at a secret, and your app reads it like any other setting.
Managed identity removes most secrets, but not all of them. A third-party API key or a partner's client secret still has to live somewhere. That somewhere should be Azure Key Vault, not an app setting typed into the portal.
The good news: you don't have to change your code to read from Key Vault.
Point an app setting at a secret
In App Service or Azure Functions, set the value of an app setting to a Key Vault reference:
@Microsoft.KeyVault(SecretUri=https://my-vault.vault.azure.net/secrets/CrmApiKey/)
or, equivalently:
@Microsoft.KeyVault(VaultName=my-vault;SecretName=CrmApiKey)
At runtime the platform resolves the reference and gives your app the secret's value. Your code still reads configuration["CrmApiKey"] or binds it through the options pattern, exactly as before.
Give the app access
The app reads the vault with its managed identity, so:
- Turn on a managed identity for the App Service or Function App.
- Grant that identity the Key Vault Secrets User role on the vault (or a secret "get" permission if the vault still uses access policies).
The portal shows a green check next to each resolved reference in Configuration. A red mark there is the first place to look when a setting comes through empty.
Rotation
If you leave the version off the reference, as in the examples above, the app uses the latest version of the secret. App Service picks up a new version automatically within 24 hours, or straight away when the app restarts or its configuration changes. Pin a version in the URI only when you want to control exactly when the change happens.
Or read Key Vault from code
Outside App Service, or when you want many secrets without adding a setting for each, add Key Vault as a configuration source:
builder.Configuration.AddAzureKeyVault(
new Uri("https://my-vault.vault.azure.net/"),
new DefaultAzureCredential());
This comes from the Azure.Extensions.AspNetCore.Configuration.Secrets package. Secret names can't contain :, so a secret named Crm--ApiKey maps to the configuration key Crm:ApiKey.
Takeaway
Store the secrets you can't eliminate in Key Vault, give the app's managed identity read access, and reference them from app settings. Your code doesn't change, and nobody needs to see or paste the secret value again.