InstrumentationKey not picked up when stored in key vault

Viewed 919

I am using a key-vault to store all the keys used in my bot v4 solution. I suspect the InstrumentationKey is not picked up correctly. What should be the name of the ApplicationInsights- InstrumentationKey in the key-vault.

In appsetting.json the key is added like this :

 "ApplicationInsights": {
    "InstrumentationKey": "xxxx-xxxx-xxx-xxxx-xxx"   }.
1 Answers

I had the same issue. These were the steps I followed to resolve it in an ASP.NET Core MVC 5 application:

  • In Program.cs file, the code for adding configuration values from Key Vault in Production environment (based on https://docs.microsoft.com/en-us/aspnet/core/security/key-vault-configuration?view=aspnetcore-5.0#use-managed-identities-for-azure-resources):

    public static IHostBuilder CreateHostBuilder(string[] args) =>
         Host.CreateDefaultBuilder(args)
             .ConfigureAppConfiguration((context, config) =>
             {
                 if (context.HostingEnvironment.IsProduction())
                 {
                     var builtConfig = config.Build();
    
                     var azureServiceTokenProvider = new AzureServiceTokenProvider();
                     var keyVaultClient = new KeyVaultClient(
                         new KeyVaultClient.AuthenticationCallback(
                             azureServiceTokenProvider.KeyVaultTokenCallback));
    
                     config.AddAzureKeyVault(
                         $"https://{builtConfig["KeyVaultName"]}.vault.azure.net/",
                         keyVaultClient,
                         new DefaultKeyVaultSecretManager());
                 }
             })
             .ConfigureWebHostDefaults(webBuilder =>
             {
                 webBuilder.UseStartup<Startup>();
             });
    
  • In Azure Key Vault create a new secret with the name "ApplicationInsights--InstrumentationKey" and give it the value of the production application insights instrumentation key. In order for your app service to be able to communicate with the key vault and read the secrets, you need to firstly enable the system assigned service identity for your azure app service and then create a key vault Access Policy for Get, List operations for secrets and assign the policy to the previously created system assigned service identity.

  • In appSettings.Production.json file:

     {
      "Logging": {
         "LogLevel": {
           "Default": "Information",
           "Microsoft": "Warning",
           "Microsoft.Hosting.Lifetime": "Information"
         }
       },
       "KeyVaultName": "{your-keyvault-name}",
       "ApplicationInsights": {
         "CloudRoleName": "TinyCrm.Web.Prod",
         "DisableTelemetry": false,
         "EnableAdaptiveSampling": true
       }
     }
    
  • To register the application insights specific stuff for the aspnet core DI framework I created the following extension method. I am using Microsoft.ApplicationInsights.AspnetCore version 2.17.0 nuget package. (taking into consideration what is written here https://docs.microsoft.com/en-us/azure/azure-monitor/app/asp-net-core#user-secrets-and-other-configuration-providers):

     public static IServiceCollection AddApplicationInsights(this IServiceCollection services, IConfiguration configuration)
     {
         // Register the settings for "ApplicationInsights" section as a service for injection from DI container
         var applicationInsightsSettings = new ApplicationInsightsSettings();
         configuration.Bind(ApplicationInsightsSettings.ApplicationInsightsSectionKey, applicationInsightsSettings);
         services.AddSingleton(applicationInsightsSettings);
    
         // Use telemetry initializers when you want to enrich telemetry with additional information
         services.AddSingleton<ITelemetryInitializer, CloudRoleTelemetryInitializer>();
    
         // Remove a specific built-in telemetry initializer
         var telemetryInitializerToRemove = services.FirstOrDefault<ServiceDescriptor>
                             (t => t.ImplementationType == typeof(AspNetCoreEnvironmentTelemetryInitializer));
    
         if (telemetryInitializerToRemove != null)
         {
             services.Remove(telemetryInitializerToRemove);
         }
    
         // You can add custom telemetry processors to TelemetryConfiguration by using the extension method AddApplicationInsightsTelemetryProcessor on IServiceCollection. 
         // You use telemetry processors in advanced filtering scenarios
         services.AddApplicationInsightsTelemetryProcessor<StaticWebAssetsTelemetryProcessor>();
    
         // The following line enables Application Insights telemetry collection.
         services.AddApplicationInsightsTelemetry();
    
         return services;
     }
    
  • In Startup.cs file:

     public void ConfigureServices(IServiceCollection services)
     {
         services.AddControllersWithViews();
    
         // Call the extension method we created above
         services.AddApplicationInsights(Configuration);
     }
    
  • Important note: Make sure when you create the new Azure App Service to not enable the Application Insights Telemetry integration automatically from the Azure app service creation wizard (see below image). Instead create the application insights resource yourself and setup your app to use the instrumentation key in production environment through following the above steps.

Azure App Service Creation Wizard

Related