Azure / Azure/azure-sdk-tools

Investigate on-demand live test secret helper

Open
#2,934 1 comment 1 reaction 0 assignees View on GitHub
Central-EngSys
Dominant language
C#
Stars
135
Forks
260
Avg merge
3d 1h
Merged PRs (30d)
144

Description

ARM deployment output values are available to anyone with read access to the subscription, so for example if a service dumps out some connection strings for a static resource, anyone with subscription read access can go look those up. If we can get all the languages using a common test env lookup helper, then we can transition to a solution that doesn't use ARM deployment outputs for common or service-specific secrets and rather have secrets go into something more on-demand like a keyvault.

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start by tracing how ARM deployment outputs currently expose test secrets across languages and documenting the existing helper patterns; done means a concrete investigation result for a common on-demand lookup approach and its effect on service-specific secrets.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
security, testing, tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.