Skip to main content

loaders.keyvault

KeyVault Objects​

class KeyVault()

Reads secrets from an Azure Key Vault by its short name.

The vault url is derived from that name, so a caller passes mykeyvault rather than https://mykeyvault.vault.azure.net. Both read paths return the secret value as a string and neither caches it.

Arguments:

  • keyvault str - Short name of the vault, without scheme or domain.
  • credential - Credential used for the SDK path. Defaults to DefaultAzureCredential(), which in a Fabric notebook resolves to the identity the notebook runs as.

get_kv_secret​

def get_kv_secret(secret: str)

Reads a secret through the Key Vault SDK, with this instance's credential.

Arguments:

  • secret str - Name of the secret in the vault.

Returns:

  • str - The current value of the secret.

Raises:

  • Exception - Propagated from the SDK when the vault or the secret cannot be reached, or when the credential is not authorized for it.

get_kv_secret_with_token​

def get_kv_secret_with_token(secret_name: str, token: str)

Reads a secret over the Key Vault REST api with a bearer token.

The alternative to get_kv_secret for callers that already hold a token for scope https://vault.azure.net/.default — from Principal.get_bearer_token, for instance — and therefore need no credential of their own. The api version is pinned to 7.4.

Arguments:

  • secret_name str - Name of the secret in the vault.
  • token str - Bearer token valid for the Key Vault scope.

Returns:

  • str - The current value of the secret.

Raises:

  • requests.HTTPError - When the vault answers with a non-success status, for example an expired token or a secret that does not exist.