← AI-200: cloud development for AI solutions
05 / 6 · 40 MIN

Secrets, configuration, and context

Coordinate configuration changes and retain controlled access and correlation.

Concept and mechanism

Key Vault stores secrets, but writing a new version does not automatically update the target credential or every consumer. Rotation needs sequencing, validation, and recovery for intermediate states. Prefer managed identity when the service and scenario support it; when a legacy secret exists, manage versions, access, and refresh. Resource management and data access are distinct boundaries: viewing the vault does not establish permission to read secrets. App Configuration separates application configuration. Labels organize values but can remain mutable; snapshots reference an immutable set for a release. That reference helps restore the exact approved values rather than reconstructing them from memory during an incident.

Guided application

In fictional rotation, some replicas pin an old version while others receive the new one. Compare version and configuration metadata without copying credentials into logs. Also confirm the credential accepted by the target through a controlled check. For dynamic Python configuration, integrate the provider refresh mechanism and observe interval and sentinel behavior; setting an interval does not necessarily create autonomous polling. Link the change to the release and record when each consumer applied it. In distributed systems, propagate trace context through HTTP and messaging to follow the same request. One fixed ID for every request mixes operations; a different trace at each boundary loses the link. Correlation should enable diagnosis without transporting secrets.

IN PRACTICE

Same secret name, different versions: intermittency can follow the replica receiving the request.

Common pitfalls

Updated vault as updated target; management Reader as secret access; label as snapshot; interval as guaranteed polling; secret as trace identifier.

Related topics: Containers, artifacts, and revisions · Cosmos DB, vectors, and change feed · PostgreSQL, vectors, and caching

Take this idea with you

Establish the effective configuration and identity at each consumer.

Create account

Reference: Secret rotation and consumer coordination · AI-200 current guide updated2026-05-05; Azure technical documentation2026-09-30