With app settings written as @Microsoft.KeyVault(...), App Service and Azure Functions pull secret values from Key Vault, so no code change is needed.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Key Vault references in context, with comparison tables and the common traps.
Terms in this definition
- App settings
Environment variables injected into an App Service app as name/value pairs, taking precedence over values in appsettings.json or Web.config. Each can be marked as specific to a slot.
- Microsoft.KeyVault
Namespace of the Key Vault resource provider, with actions such as Microsoft.KeyVault/vaults/write; it is also what the Key Vault service endpoint is called.
- App Service
Managed PaaS hosting for web apps and Web App for Containers, run in a sandbox without OS access. Deployment slots and autoscale start at the Standard tier.
- Authorisation levels
Key requirements for HTTP triggers in Azure Functions: Anonymous needs no key, Function accepts a function or host key, and Admin requires the master key.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
- VALUES
Returns in DAX the distinct column values, or table rows, still visible after filters are applied, sometimes with an extra blank entry. CALCULATE often takes the result as a table filter.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
Related terms
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.