Azure CLI ARM parameters json using variables to retrieve keyvault secrets

Viewed 1073

We've created a bash script to rollout our Azure infrastructure based on Azure CLI & ARM Templates.

We also use keyvault to store our secrets and we need to it for references when deploying resources.

Example (this works with static values in the parameters json):

templateUri="armdeploymysql.json"
az group deployment create \
    --name $Environment \
    --resource-group $RSGName \
    --template-file $templateUri \
    --parameters @armdeploymysql-parameters.json

In the armdeploymysql-parameters.json you find this:

{
    "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#",
    "contentVersion": "1.0.0.0",
    "parameters": {
        "administratorLogin": {
            "value": "termysqladmin"
        },
        "administratorLoginPassword": {
            "reference": {
              "keyVault": {
                "id": "/subscriptions/xxx-xxx-xxx-xxx--xx/resourceGroups/resourcegroupname/providers/Microsoft.KeyVault/vaults/keyvaultname"
              },
              "secretName": "WORDPRESSDBPASSWORD"
            }
        },

As you can see we are using static values. But we need to deploy this template for multiple environments (Test, Acc & Prod), so we would like to use variables instead of static values.

It works for most of the ARM parameters and we used configure it like:

templateUri="armdeploymysql.json"
az group deployment create \
    --name $Environment \
    --resource-group $RSGName \
    --template-file $templateUri \
    --parameters "version=$version" \
                 "location=$location" \
                 "administratorLogin=$SQLAdmin" \
                 "administratorLoginPassword=$SQLPass"

So the question is:

  1. Can we make a parameter reference like the last example to point to a keyvault?
  2. How can we parse variables in the parameters json?
2 Answers

Why don't you use az to get the secret, and then pass it to your template.

WpPwd = az keyvault secret show --vault-name "keyvaultname" --name "WORDPRESSDBPASSWORD"

templateUri="armdeploymysql.json"
az group deployment create \
    --name $Environment \
    --resource-group $RSGName \
    --template-file $templateUri \
    --parameters "version=$version" \
                 "location=$location" \
                 "administratorLogin=$SQLAdmin" \
                 "administratorLoginPassword=$SQLPass"
                 "wordpresspassword=$WpPwd"

Final fix for this specific case (credits to @Murray Foxcroft), snippet from the code:

keyVaultName="keyvaultname-$Environment"
keyVaultsecret="WORDPRESSDBPASSWORD"
SQLPass=$(az keyvault secret show --vault-name $keyVaultName --name $keyVaultsecret --query value -o tsv)

az group deployment create \
    --name $Environment \
    --resource-group $RSGName \
    --template-file $templateUri \
    --parameters "version=$version" \
                 "location=$location" \
                 "administratorLogin=$SQLAdmin" \
                 "administratorLoginPassword=$SQLPass" \

The -o tsv was important to avoid adding the extra characters that the normal command passes to the variable.

Thanks for the help!

Related