Azure Key Vault密钥自动轮换:提前告警及全自动化流程实现咨询
Great question! Since you already have a working Azure Automation Runbook for key rotation, let's build out the alerting, auto-trigger, and VSTS Build integration to make this a fully automated pipeline. Here's a practical, step-by-step breakdown:
First, you need to set up alerts to notify you when keys are approaching their expiration date, and hook those alerts up to trigger your rotation runbook. Here's how:
- Go to your Azure Key Vault in the portal, then navigate to Alerts > Create > Alert rule
- Under "Condition", select Signal type: Metric, then pick the
Key Expirationmetric. Set your threshold (e.g., alert when a key expires in <30 days) - In the "Actions" tab, create an Action Group that includes two actions:
- A notification action (email, Teams, SMS) to alert your team that a key is due for rotation
- A Runbook action: Select your existing Automation Account, choose your rotation runbook, and pass in parameters like the key vault name and key name (you can use alert context variables here, e.g.,
{{$ResourceName}}for the vault name)
- Make sure the Azure Monitor service principal has permissions to start runbooks in your Automation Account (grant the
Automation Job Operatorrole on the account if needed)
Your runbook already works manually, but when triggered by Azure Monitor, it needs the right permissions via a managed identity:
- Go to your Automation Account > Identity and enable the System-assigned managed identity
- Navigate back to your Key Vault, go to Access policies > Add access policy
- Grant the managed identity the following key permissions:
Rotate,Get,List,Create(adjust based on your runbook's specific needs) - This avoids hardcoded credentials and keeps your setup secure and maintainable
To tie everything into VSTS Build (now Azure DevOps Build), you can create a pipeline that orchestrates rotation, validation, and any downstream configuration updates. Here's how to structure it:
- Create a new Build Pipeline in Azure DevOps, linked to your repo (even if it's just a repo for pipeline definitions)
- Add these tasks to your pipeline:
- Azure PowerShell Task: Use this to start your Automation runbook with a command like:
Start-AzAutomationRunbook -AutomationAccountName "your-automation-account" -Name "your-rotation-runbook" -Parameters @{VaultName = "your-key-vault"; KeyName = "$(KeyName)"} - Wait & Verify Task: Add a loop or delay to wait for the runbook job to complete, then check its status with
Get-AzAutomationJob - Validation Task: Use Azure CLI to confirm the new key version exists and is active:
az keyvault key list-versions --vault-name "your-key-vault" --name "$(KeyName)" --query "[0].attributes.enabled" - Downstream Sync Task: If your apps/services rely on this key, add steps to update their configurations (e.g., update App Service settings, push changes to a config repo)
- Azure PowerShell Task: Use this to start your Automation runbook with a command like:
- To trigger this pipeline automatically when an alert fires:
- In your Azure Monitor alert's Action Group, add a Webhook action that calls the Azure DevOps Build API endpoint
- Pass a request body with your pipeline ID and required parameters, using a PAT token with Build permissions for authentication
- Test End-to-End: Create a test key with an expiration date 1 day out to verify alerts fire, runbooks trigger, and the VSTS pipeline executes correctly
- Log Everything: Enable runbook logging to Log Analytics (in Automation Account > Diagnostic settings) and add logging steps to your VSTS pipeline—this makes troubleshooting way easier if something breaks
- Least Privilege Permissions: Only grant the managed identity and VSTS service connection the exact permissions they need, nothing more
- Rollback Logic: If rotation fails, include steps in your runbook or VSTS pipeline to revert to the previous key version and send an urgent alert to your team
内容的提问来源于stack exchange,提问作者Mani

