easyfabric.loaders.keyvault
KeyVault Objects
class KeyVault()
Reads secrets from an Azure Key Vault by its short name.
The vault url is derived from that name, so a caller passes mykeyvault
rather than https://mykeyvault.vault.azure.net. Both read paths return the
secret value as a string and neither caches it.
Arguments:
keyvaultstr - Short name of the vault, without scheme or domain.credential- Credential used for the SDK path. Defaults toDefaultAzureCredential(), which in a Fabric notebook resolves to the identity the notebook runs as.
get_kv_secret
def get_kv_secret(secret: str)
Reads a secret through the Key Vault SDK, with this instance's credential.
Arguments:
secretstr - Name of the secret in the vault.
Returns:
str- The current value of the secret.
Raises:
Exception- Propagated from the SDK when the vault or the secret cannot be reached, or when the credential is not authorized for it.
get_kv_secret_with_token
def get_kv_secret_with_token(secret_name: str, token: str)
Reads a secret over the Key Vault REST api with a bearer token.
The alternative to get_kv_secret for callers that already hold a token
for scope https://vault.azure.net/.default — from
Principal.get_bearer_token, for instance — and therefore need no
credential of their own. The api version is pinned to 7.4.
Arguments:
secret_namestr - Name of the secret in the vault.tokenstr - Bearer token valid for the Key Vault scope.
Returns:
str- The current value of the secret.
Raises:
requests.HTTPError- When the vault answers with a non-success status, for example an expired token or a secret that does not exist.