Azure Key Vault (store: azure-keyvault)

Resolves secret values from an Azure Key Vault instance — via the real Azure SDK (azure-keyvault-secrets), not the az CLI.

Prerequisites

  • An Azure Key Vault with the secrets you want to use already populated.

  • The identity strata runs as must have Key Vault Secrets User (or equivalent) access on that vault — see Authentication below for how that identity is chosen.

Authentication — ambient, via DefaultAzureCredential, never spec.authentication

kind: integration’s spec.authentication field is not used here, deliberately — see docs/design/store-integration-configuration.md for the full reasoning. In short: DefaultAzureCredential’s entire point is not needing an explicit credential value — it chains through managed identity, workload identity/OIDC, then az login, automatically, with nothing to declare in the common case (a managed identity assigned to the resource strata runs on).

Env var

Required

Purpose

AZURE_KEYVAULT_URL

Yes

The vault’s URL, e.g. https://my-vault.vault.azure.net

AZURE_CLIENT_ID

Only for a user-assigned managed identity

Picked up automatically by DefaultAzureCredential itself — not strata-specific

If none of DefaultAzureCredential’s chain applies (e.g. running fully locally, outside Azure), set whichever of its own supported env vars match your situation (AZURE_TENANT_ID/AZURE_CLIENT_ID/AZURE_CLIENT_SECRET for a service principal) — this is the SDK’s own mechanism, not something strata adds or needs to know about.

Configuring the kind: integration document (optional)

Everything above already works with no kind: integration document at all — AZURE_KEYVAULT_URL alone is enough. Declare one when you want the vault URL checked into the solution itself instead of living only in an env var:

apiVersion: strata.huybrechts.xyz/v2
kind: integration
meta:
  name: azure-keyvault-prod
spec:
  type: azure-keyvault
  capabilities: [secrets]
  enabled: true
  endpoints:
    address: https://my-vault.vault.azure.net

Using it from an Environment

apiVersion: strata.huybrechts.xyz/v2
kind: environment
meta:
  name: prd
spec:
  secrets:
    - key: DB_PASSWORD
      store: azure-keyvault
      value: db-password # the secret's own name in the vault

value is the secret’s own name inside the vault — not a strata-declared key, and not a literal value.

Troubleshooting

  • “AZURE_KEYVAULT_URL is not set” — neither the env var nor a kind: integration document’s endpoints.address resolved to a URL.

  • “no secret named ‘…’ in ‘…’” — the secret name doesn’t exist in that vault; check for a typo or the wrong vault URL.

  • “could not resolve ‘…’: …” — usually an authentication/authorization failure; confirm the identity DefaultAzureCredential picked has Key Vault Secrets User (or broader) access on the vault.

  • Multiple candidates named ‘…’ — set ‘integration:’ explicitly” (once the binding design is implemented) — more than one enabled kind: integration document declares type: azure-keyvault. Disable all but one — a store cannot name which one to use by itself.