Concept and mechanism
Key Vault stores secrets, but writing a new version does not automatically update the target credential or every consumer. Rotation needs sequencing, validation, and recovery for intermediate states. Prefer managed identity when the service and scenario support it; when a legacy secret exists, manage versions, access, and refresh. Resource management and data access are distinct boundaries: viewing the vault does not establish permission to read secrets. App Configuration separates application configuration. Labels organize values but can remain mutable; snapshots reference an immutable set for a release. That reference helps restore the exact approved values rather than reconstructing them from memory during an incident.
Guided application
In fictional rotation, some replicas pin an old version while others receive the new one. Compare version and configuration metadata without copying credentials into logs. Also confirm the credential accepted by the target through a controlled check. For dynamic Python configuration, integrate the provider refresh mechanism and observe interval and sentinel behavior; setting an interval does not necessarily create autonomous polling. Link the change to the release and record when each consumer applied it. In distributed systems, propagate trace context through HTTP and messaging to follow the same request. One fixed ID for every request mixes operations; a different trace at each boundary loses the link. Correlation should enable diagnosis without transporting secrets.
Same secret name, different versions: intermittency can follow the replica receiving the request.
Common pitfalls
Updated vault as updated target; management Reader as secret access; label as snapshot; interval as guaranteed polling; secret as trace identifier.
Related topics: Containers, artifacts, and revisions · Cosmos DB, vectors, and change feed · PostgreSQL, vectors, and caching
Establish the effective configuration and identity at each consumer.
Reference: Secret rotation and consumer coordination · AI-200 current guide updated2026-05-05; Azure technical documentation2026-09-30