Q: How do you ensure secure and dynamic secret rotation in Azure DevOps pipelines?
How to design dynamic, zero-trust secret rotation in Azure DevOps CI/CD pipelines eliminating static passwords and long-lived service principal keys.
Master cloud-native security and container runtime defense: Prepare with KodeKloud's CKS course with live browser-based terminal sandboxes.
🛠️ Production Runbook & Step-by-Step Resolution
Eliminate Passwords via OIDC Workload Identity Federation
Configure Azure DevOps Service Connections with Workload Identity Federation instead of static client secrets. When a pipeline runs, Azure DevOps generates a short-lived cryptographically signed OIDC token that Azure Active Directory exchanges for a temporary, 1-hour Azure access token.
# Azure DevOps YAML using federated service connection
steps:
- task: AzureCLI@2
inputs:
azureSubscription: 'Azure-DevOps-WorkloadIdentity-ServiceConnection'
scriptType: 'bash'
scriptLocation: 'inlineScript'
inlineScript: |
az account show
Dynamic Secret Retrieval from Azure Key Vault
Never store application database credentials in pipeline YAML. Use the `AzureKeyVault@2` pipeline task to dynamically pull the latest active secret version directly into agent memory at execution time. Secrets are masked in logs automatically.
- task: AzureKeyVault@2
inputs:
azureSubscription: 'Azure-DevOps-WorkloadIdentity-ServiceConnection'
KeyVaultName: 'kv-prod-banking'
SecretsFilter: 'DB-PASSWORD,STRIPE-SECRET'
RunAsPreJob: true
Automate Secret Rotation via Event Grid & Azure Functions
Configure Azure Key Vault automatic rotation policies. When a database password reaches its 30-day lifecycle expiration, Key Vault triggers an Azure Event Grid event to an Azure Function, which generates a new password, updates PostgreSQL/SQL Server, and stores the new secret version in Key Vault with zero downtime.
Enforce Dual-Credential Overlap for Zero-Downtime Rotation
During rotation, configure the database with two active users (User A and User B). When User A's password rotates, services gracefully transition to User B without connection drops before User A's credentials are wiped.
- Migrate Azure DevOps service connections to OIDC Workload Identity Federation to eliminate static client secrets.
- Fetch secrets dynamically in pipeline memory via AzureKeyVault@2 rather than storing them in variables.
- Automate rotation policies in Key Vault using Event Grid and Azure Functions for automated 30-day key updates.
- Implement dual-credential rotation patterns to ensure zero downtime while database passwords cycle.