You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Camel/SpringBoot中从Azure Key Vault加载Bean属性值

实现从Azure Key Vault加载Bean属性的方案

1. 添加依赖

在Maven项目的pom.xml中引入Spring Cloud Azure Key Vault Secrets启动器:

<dependency>
    <groupId>com.azure.spring</groupId>
    <artifactId>spring-cloud-azure-starter-keyvault-secrets</artifactId>
    <!-- 使用与Spring Boot版本匹配的最新稳定版 -->
    <version>4.12.0</version>
</dependency>
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter</artifactId>
</dependency>

2. 配置Azure Key Vault连接信息

在application.properties(或application.yml)中配置Key Vault的访问参数:

# 替换为你的Key Vault地址
spring.cloud.azure.keyvault.secrets.endpoint=https://your-vault-name.vault.azure.net/

# 本地开发用服务主体认证(生产环境优先用托管身份)
spring.cloud.azure.keyvault.secrets.client-id=your-service-principal-client-id
spring.cloud.azure.keyvault.secrets.client-secret=your-service-principal-client-secret
spring.cloud.azure.keyvault.secrets.tenant-id=your-azure-ad-tenant-id

如果使用Azure托管身份(无需客户端ID和密钥),仅保留endpoint配置即可,程序会自动通过托管身份获取访问权限。

3. 配置占位符解析以支持${azure:xxx}格式

创建Java配置类,注册自定义的属性占位符解析器,将Key Vault密钥加载到名为azure的属性源中:

import com.azure.spring.cloud.autoconfigure.keyvault.secrets.AzureKeyVaultProperties;
import com.azure.spring.cloud.keyvault.secrets.AzureKeyVaultPropertySource;
import com.azure.security.keyvault.secrets.SecretClient;
import com.azure.security.keyvault.secrets.SecretClientBuilder;
import com.azure.identity.DefaultAzureCredentialBuilder;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.context.support.PropertySourcesPlaceholderConfigurer;

@Configuration
public class AzureKeyVaultConfig {

    // 配置占位符规则,支持${azure:type}格式解析
    @Bean
    public PropertySourcesPlaceholderConfigurer propertySourcesPlaceholderConfigurer() {
        PropertySourcesPlaceholderConfigurer configurer = new PropertySourcesPlaceholderConfigurer();
        // 设置分隔符为冒号,解析时会从"azure"属性源中读取对应key的值
        configurer.setSeparator(":");
        // 忽略未匹配的占位符,避免其他配置报错
        configurer.setIgnoreUnresolvablePlaceholders(true);
        return configurer;
    }

    // 将Key Vault密钥加载到名为"azure"的属性源
    @Bean
    public AzureKeyVaultPropertySource azureKeyVaultPropertySource(AzureKeyVaultProperties properties) {
        SecretClient secretClient = new SecretClientBuilder()
                .vaultUrl(properties.getEndpoint())
                .credential(new DefaultAzureCredentialBuilder()
                        .tenantId(properties.getTenantId())
                        .clientId(properties.getClientId())
                        .clientSecret(properties.getClientSecret())
                        .build())
                .buildClient();
        // 属性源名称设为"azure",对应占位符前缀
        return new AzureKeyVaultPropertySource("azure", secretClient);
    }
}

4. 验证XML Bean配置

你的现有XML Bean配置无需修改,确保Spring容器能扫描到上述配置类,即可正常解析${azure:type}和${azure:color}:

<bean id="shape1" class="shape">
    <property name='type' value='${azure:type}'/>
    <property name='color' value='${azure:color}' />
</bean>

关键注意事项

  • 确保Azure服务主体(或托管身份)拥有Key Vault的Secrets Reader权限,否则无法读取密钥。
  • 若不想自定义分隔符,可通过spring.cloud.azure.keyvault.secrets.property-name-prefix=azure.将密钥前缀设为azure.,此时占位符改为${azure.type}即可,无需修改占位符解析规则。

内容的提问来源于stack exchange,提问作者Abdelghani Tag

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 08:43:21