You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在.NET Core ASP.NET项目中,Azure Key Vault是否支持配置节?

Azure Key Vault 与 ASP.NET Core 配置节的适配方案

Azure Key Vault支持ASP.NET Core的配置节映射,只是不能直接用冒号(:)作为机密名称的分隔符——因为Key Vault的机密名称不允许包含冒号这类特殊字符。

解决方法有两种:

  • 使用双破折号(--)替代冒号:Key Vault允许双破折号,ASP.NET Core的配置提供程序会自动将双破折号转换为冒号,映射到对应的配置节。比如你想映射到Database:ConnectionString,可以在Key Vault里创建名为Database--ConnectionString的机密,程序读取时会自动识别为Database配置节下的ConnectionString键。

  • 手动配置映射规则:在启动代码里自定义机密名称到配置路径的映射,通过AzureKeyVaultConfigurationOptions的SecretNameParser来处理。示例代码如下:

builder.Configuration.AddAzureKeyVault(
    new Uri("https://your-vault-name.vault.azure.net/"),
    new DefaultAzureCredential(),
    new AzureKeyVaultConfigurationOptions
    {
        SecretNameParser = secretName =>
        {
            // 自定义转换逻辑,比如把下划线换成冒号
            var configPath = secretName.Replace("_", ":");
            return new SecretValue(configPath, secretName);
        }
    });

简言之,不是不支持配置节,只是Key Vault对机密名称的字符限制和App Service不同,换用合法分隔符或自定义转换逻辑就能实现配置节的映射。

内容的提问来源于stack exchange,提问作者Martin Staufcik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 04:26:02