⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Security & DevSecOps Interview Questions Scenario 52 of 54 in Security & DevSecOps
Senior DevSecOps / Cloud Platform Engineer Security Secret Governance & CI/CD J.P. Morgan Technical Loop

Q: How do you ensure secure and dynamic secret rotation in Azure DevOps pipelines?

How to design dynamic, zero-trust secret rotation in Azure DevOps CI/CD pipelines eliminating static passwords and long-lived service principal keys.

#Security #Azure DevOps #Azure Key Vault #Secret Rotation #OIDC #Workload Identity
🎙️ Candidate Opening & Architectural Context
"In modern enterprise banking infrastructure, storing static secrets or long-lived service principal passwords inside CI/CD variable groups is a major compliance risk. I eliminate long-lived secrets using OpenID Connect (OIDC) Workload Identity Federation between Azure DevOps and Azure AD, paired with automated Azure Key Vault dynamic secret rotation and short-lived tokens."
Advertisement
🛡️
⚡ Recommended DevSecOps Track

Master cloud-native security and container runtime defense: Prepare with KodeKloud's CKS course with live browser-based terminal sandboxes.

Prepare with KodeKloud's CKS Course →

🛠️ Production Runbook & Step-by-Step Resolution

1

Eliminate Passwords via OIDC Workload Identity Federation

Configure Azure DevOps Service Connections with Workload Identity Federation instead of static client secrets. When a pipeline runs, Azure DevOps generates a short-lived cryptographically signed OIDC token that Azure Active Directory exchanges for a temporary, 1-hour Azure access token.

# Azure DevOps YAML using federated service connection
steps:
- task: AzureCLI@2
  inputs:
    azureSubscription: 'Azure-DevOps-WorkloadIdentity-ServiceConnection'
    scriptType: 'bash'
    scriptLocation: 'inlineScript'
    inlineScript: |
      az account show
2

Dynamic Secret Retrieval from Azure Key Vault

Never store application database credentials in pipeline YAML. Use the `AzureKeyVault@2` pipeline task to dynamically pull the latest active secret version directly into agent memory at execution time. Secrets are masked in logs automatically.

- task: AzureKeyVault@2
  inputs:
    azureSubscription: 'Azure-DevOps-WorkloadIdentity-ServiceConnection'
    KeyVaultName: 'kv-prod-banking'
    SecretsFilter: 'DB-PASSWORD,STRIPE-SECRET'
    RunAsPreJob: true
Advertisement
3

Automate Secret Rotation via Event Grid & Azure Functions

Configure Azure Key Vault automatic rotation policies. When a database password reaches its 30-day lifecycle expiration, Key Vault triggers an Azure Event Grid event to an Azure Function, which generates a new password, updates PostgreSQL/SQL Server, and stores the new secret version in Key Vault with zero downtime.

Key Vault 30-Day Trigger→Event Grid Event→Azure Function Generator→Update DB Password→Commit New Key Vault Version
4

Enforce Dual-Credential Overlap for Zero-Downtime Rotation

During rotation, configure the database with two active users (User A and User B). When User A's password rotates, services gracefully transition to User B without connection drops before User A's credentials are wiped.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Replace static pipeline secrets with Azure DevOps OIDC Workload Identity Federation. Retrieve secrets dynamically from Azure Key Vault and automate database credential rotation via Event Grid and dual-credential pairing."
⚡ 60-Second Elevator Pitch Talking Points
  • Migrate Azure DevOps service connections to OIDC Workload Identity Federation to eliminate static client secrets.
  • Fetch secrets dynamically in pipeline memory via AzureKeyVault@2 rather than storing them in variables.
  • Automate rotation policies in Key Vault using Event Grid and Azure Functions for automated 30-day key updates.
  • Implement dual-credential rotation patterns to ensure zero downtime while database passwords cycle.
Advertisement
Want more Security & DevSecOps scenarios?
Explore our complete collection of scenario-based Security & DevSecOps interview runbooks.
Browse All Security & DevSecOps Questions →