String value kept in Key Vault, for example a password, connection string or API key.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Key Vault secret in context, with comparison tables and the common traps.
Terms in this definition
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- API
Short for application programming interface: a contract that client code calls programmatically, for example a web API secured with tokens or the Files, Images or Responses APIs.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID.
Related terms
- @akv()
Available since version 1.6, this function lets a Data API builder config file pull in a Key Vault secret at load time from the vault endpoint you've configured. Substitutions made with
@env()happen earlier. - Intermediate CA certificate
Used by Azure Firewall Premium to sign server certificates on the fly during TLS inspection, this CA certificate must be exportable and is kept as a Key Vault secret. A user-assigned managed identity gives the firewall access, and clients need to trust the root above it.
- Secret attributes
Properties of a Key Vault secret: Enabled, NotBefore (
nbf, when it becomes active) and Expires (exp). Disabled secrets cannot be read, whereasnbfandexpare only advisory for secrets. - URI
Identifies a resource as a string; examples include the address of a Key Vault secret and the queue service address Functions connections rely on.