Skip to content

feat(azure): read APIM header secrets from Key Vault - #15

Merged
danieltruong merged 4 commits into
mainfrom
feat-kv-refs
Sep 11, 2026
Merged

danieltruong merged 4 commits into
mainfrom
feat-kv-refs

Conversation

@danieltruong

Copy link
Copy Markdown
Collaborator

The two APIM header values become Key Vault references on the Function app, resolved by analytics-identity-<env>. The @secure() params and the deploy-time exports go away. The vault is demi-kv-<env> from eagle-demi; prod lives in rg-demi-prod, so the Secrets User grant deploys cross-RG.

Depends on eagle-demi PR #380 for demi-kv-prod. Until that vault exists, a prod deploy fails on the missing vault instead of deploying an empty value.

Function app settings become Key Vault references resolved by the
analytics identity; the two @secure() params and their GitHub feeds go.
Prod vault lives in rg-demi-prod, so the grant runs cross-RG.
The two header app settings are Key Vault references against
demi-kv-<env>, which has public network access disabled. App Service
resolves a reference with a data-plane GET over the app's own outbound
path and is not a Key Vault trusted service, so with no subnet both
settings resolve to nothing and every guarded route answers 401.

vnetSubnetId is required and has no default. Both param files name
snet-demi-func-fc1-<env>, the landing-zone subnet delegated to
Microsoft.App/environments that demi-api-fc-<env> already integrates
with. It is a /27, so raising either app's maximumInstanceCount needs a
wider subnet first.

The two secret names become template variables: nothing varied them per
environment.
App Service passes '@Microsoft.KeyVault(SecretUri=...)' through as the
setting value when it cannot read the secret. That string is composed
only from names published in this repo, so the header guards would have
compared requests against a value anyone can reconstruct, and the
non-empty boot check accepted it because it is not empty.

A secret setting holding a reference now reads as unset, so the existing
fail-closed path fires and names the setting. MIGRATION.md gains the
vault-secret step the first deploy depends on.
@danieltruong
danieltruong merged commit 611480e into main Sep 11, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant