feat(azure): read APIM header secrets from Key Vault - #15
Merged
Merged
Conversation
Function app settings become Key Vault references resolved by the analytics identity; the two @secure() params and their GitHub feeds go. Prod vault lives in rg-demi-prod, so the grant runs cross-RG.
The two header app settings are Key Vault references against demi-kv-<env>, which has public network access disabled. App Service resolves a reference with a data-plane GET over the app's own outbound path and is not a Key Vault trusted service, so with no subnet both settings resolve to nothing and every guarded route answers 401. vnetSubnetId is required and has no default. Both param files name snet-demi-func-fc1-<env>, the landing-zone subnet delegated to Microsoft.App/environments that demi-api-fc-<env> already integrates with. It is a /27, so raising either app's maximumInstanceCount needs a wider subnet first. The two secret names become template variables: nothing varied them per environment.
App Service passes '@Microsoft.KeyVault(SecretUri=...)' through as the setting value when it cannot read the secret. That string is composed only from names published in this repo, so the header guards would have compared requests against a value anyone can reconstruct, and the non-empty boot check accepted it because it is not empty. A secret setting holding a reference now reads as unset, so the existing fail-closed path fires and names the setting. MIGRATION.md gains the vault-secret step the first deploy depends on.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The two APIM header values become Key Vault references on the Function app, resolved by
analytics-identity-<env>. The@secure()params and the deploy-time exports go away. The vault isdemi-kv-<env>from eagle-demi; prod lives inrg-demi-prod, so the Secrets User grant deploys cross-RG.Depends on eagle-demi PR #380 for
demi-kv-prod. Until that vault exists, a prod deploy fails on the missing vault instead of deploying an empty value.