快速入門:使用 ARM 範本從 Azure Key Vault 設定並取得秘密

Azure Key Vault 是一項雲端服務,提供一個安全的秘密儲存,例如金鑰、密碼、憑證及其他秘密。 這個快速入門重點介紹部署 Azure Resource Manager 範本(ARM 範本)以建立金鑰保險庫與秘密的過程。

Azure Resource Manager 模板 是一個 JavaScript 物件符號(JSON)檔案,用來定義你專案的基礎架構與設定。 範本使用宣告式語法。 您可以描述預期的部署,而不需要撰寫程式設計命令順序來建立部署。

如果你的環境符合前提條件,且熟悉使用 ARM 範本,請選擇 部署到 Azure 按鈕。 範本會在 Azure 入口網站開啟。

按鈕,將Resource Manager範本部署到 Azure.

先決條件

以下是完成本文的步驟:

  • 如果你沒有Azure訂閱,請在開始前建立一個free帳號。

檢閱範本

這個快速入門中使用的範本來自 Azure Quickstart Templates。

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "metadata": {
    "_generator": {
      "name": "bicep",
      "version": "0.42.1.51946",
      "templateHash": "10998800669048245550"
    }
  },
  "parameters": {
    "keyVaultName": {
      "type": "string",
      "metadata": {
        "description": "Specifies the name of the key vault."
      }
    },
    "location": {
      "type": "string",
      "defaultValue": "[resourceGroup().location]",
      "metadata": {
        "description": "Specifies the Azure location where the key vault should be created."
      }
    },
    "enabledForDeployment": {
      "type": "bool",
      "defaultValue": false,
      "metadata": {
        "description": "Specifies whether Azure Virtual Machines are permitted to retrieve certificates stored as secrets from the key vault."
      }
    },
    "enabledForDiskEncryption": {
      "type": "bool",
      "defaultValue": false,
      "metadata": {
        "description": "Specifies whether Azure Disk Encryption is permitted to retrieve secrets from the vault and unwrap keys."
      }
    },
    "enabledForTemplateDeployment": {
      "type": "bool",
      "defaultValue": false,
      "metadata": {
        "description": "Specifies whether Azure Resource Manager is permitted to retrieve secrets from the key vault."
      }
    },
    "tenantId": {
      "type": "string",
      "defaultValue": "[subscription().tenantId]",
      "metadata": {
        "description": "Specifies the Azure Active Directory tenant ID that should be used for authenticating requests to the key vault. Get it by using Get-AzSubscription cmdlet."
      }
    },
    "skuName": {
      "type": "string",
      "defaultValue": "standard",
      "allowedValues": [
        "standard",
        "premium"
      ],
      "metadata": {
        "description": "Specifies whether the key vault is a standard vault or a premium vault."
      }
    },
    "secretsObject": {
      "type": "secureObject",
      "metadata": {
        "description": "Specifies all secrets {\"secretName\":\"\",\"secretValue\":\"\"} wrapped in a secure object."
      }
    }
  },
  "resources": [
    {
      "type": "Microsoft.KeyVault/vaults",
      "apiVersion": "2023-07-01",
      "name": "[parameters('keyVaultName')]",
      "location": "[parameters('location')]",
      "properties": {
        "enabledForDeployment": "[parameters('enabledForDeployment')]",
        "enabledForTemplateDeployment": "[parameters('enabledForTemplateDeployment')]",
        "enabledForDiskEncryption": "[parameters('enabledForDiskEncryption')]",
        "enableRbacAuthorization": true,
        "tenantId": "[parameters('tenantId')]",
        "enableSoftDelete": true,
        "softDeleteRetentionInDays": 90,
        "enablePurgeProtection": true,
        "sku": {
          "name": "[parameters('skuName')]",
          "family": "A"
        },
        "networkAcls": {
          "defaultAction": "Allow",
          "bypass": "AzureServices"
        }
      }
    },
    {
      "copy": {
        "name": "secrets",
        "count": "[length(parameters('secretsObject').secrets)]"
      },
      "type": "Microsoft.KeyVault/vaults/secrets",
      "apiVersion": "2023-07-01",
      "name": "[format('{0}/{1}', parameters('keyVaultName'), parameters('secretsObject').secrets[copyIndex()].secretName)]",
      "properties": {
        "value": "[parameters('secretsObject').secrets[copyIndex()].secretValue]"
      },
      "dependsOn": [
        "[resourceId('Microsoft.KeyVault/vaults', parameters('keyVaultName'))]"
      ]
    }
  ],
  "outputs": {
    "location": {
      "type": "string",
      "value": "[parameters('location')]"
    },
    "name": {
      "type": "string",
      "value": "[parameters('keyVaultName')]"
    },
    "resourceGroupName": {
      "type": "string",
      "value": "[resourceGroup().name]"
    },
    "resourceId": {
      "type": "string",
      "value": "[resourceId('Microsoft.KeyVault/vaults', parameters('keyVaultName'))]"
    }
  }
}

模板中定義了兩個 Azure 資源:

由於保存庫使用 Azure RBAC 進行資料平面授權,因此您是透過指派 Azure 角色來授與秘密的存取權 (而非透過設定存取原則)。

更多Azure Key Vault範本範例可見於Azure快速入門範本。

部署範本

  1. 選擇以下圖片登入 Azure 並開啟範本。 此範本會建立金鑰保存庫和祕密。

    按鈕,將Resource Manager範本部署到 Azure.

  2. 選取或輸入下列值。 除非特別指定,否則就用預設值。

    • Subscription:選擇Azure訂閱。

    • 資源群組:選取 [新建],輸入資源群組的唯一名稱,然後選取 [確認]。

    • 區域:選擇地點。 例如,美國中部。

    • 金鑰保存庫 Name:為key vault輸入名稱,且必須在 vault.azure.net 命名空間中全域唯一。 當你在下一節驗證部署時,會需要這個名稱。

    • SKU 名稱:選擇 標準 或 高級。 預設是 標準。

    • Secrets 物件:提供要建立的一或多個 Secret,格式為包含 secrets 陣列的 JSON 物件。 例如:

      {
        "secrets": [
          {
            "secretName": "adminpassword",
            "secretValue": "<your-secret-value>"
          }
        ]
      }
      

      因為 Secrets Object 是一個 secureObject 參數,部署後不會記錄或回傳它的值。

  3. 選取 [檢閱 + 建立],然後選取 [建立]。 金鑰保存庫與秘密成功部署之後,您會收到通知。

你也可以使用 Azure PowerShell、Azure CLI 或 REST API 來部署範本。 若要了解其他部署方法,請參閱部署範本。

指派 金鑰保存庫 RBAC 角色

此範本所建立的金鑰庫使用Azure RBAC授權。 要透過資料平面存取秘密(例如使用 Azure CLI 或 Azure PowerShell),你需要為自己指定一個適當的角色。

  1. 取得您的 Microsoft Entra 使用者物件 ID:

    az ad signed-in-user show --query id -o tsv
    
  2. 在金鑰保存庫上將 金鑰保存庫祕密管理員 角色指派給自己:

    echo "Enter your key vault name:" &&
    read keyVaultName &&
    az role assignment create --role "Key Vault Secrets Officer" \
        --assignee-object-id $(az ad signed-in-user show --query id -o tsv) \
        --scope $(az keyvault show --name $keyVaultName --query id -o tsv)
    

    Note

    角色指派可能需要一兩分鐘才會生效。

檢閱已部署的資源

你可以使用 Azure 入口網站檢查金鑰庫和秘密,或使用以下 Azure CLI 或 Azure PowerShell 腳本列出已建立的秘密。

echo "Enter your key vault name:" &&
read keyVaultName &&
az keyvault secret list --vault-name $keyVaultName &&
echo "Press [ENTER] to continue ..."

清理資源

其他 金鑰保存庫 快速入門與教學則在此快速入門基礎上延伸。 如果您打算繼續進行後續的快速入門和教學課程,您可以讓這些資源留在原處。 不再需要時,刪除資源群組,這樣 金鑰保存庫 和相關資源就會被刪除。 使用 Azure CLI 或 Azure PowerShell 刪除資源群組:

echo "Enter the Resource Group name:" &&
read resourceGroupName &&
az group delete --name $resourceGroupName &&
echo "Press [ENTER] to continue ..."

Note

刪除資源群組也會刪除金鑰庫,但金庫會進入軟刪除狀態,並在保留期間(預設為 90 天)內仍可恢復。 在此期間,該保存庫名稱仍會在全域保留,而且因為已啟用清除保護,所以無法提前清除該保存庫。 對於標準金鑰保存庫,虛刪除的保存庫不會產生費用。 更多資訊請參見 金鑰保存庫 軟刪除概覽。

後續步驟

在本快速入門中,您已使用 ARM 範本建立金鑰保存庫和秘密,並驗證部署。 想了解更多關於 金鑰保存庫 和 Azure Resource Manager 的資訊,請繼續閱讀以下文章。