PageSourceSearch

https://arcus-background-jobs.netlify.app/assets/js/146f0b06.45dfbc6a.js

js arcus-background-jobs.netlify.app collected 2026-10-03 10:28:42 UTC 5,678 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkarcus_background_jobs=self.webpackChunkarcus_background_jobs||[]).push([[752],{6182:(e,t,r)=>{r.r(t),r.d(t,{assets:()=>a,contentTitle:()=>c,default:()=>d,frontMatter:()=>s,metadata:()=>o,toc:()=>u});var n=r(6070),i=r(7468);const s={title:"Automatically Invalidate Azure Key Vault Secrets",layout:"default"},c="Automatically Invalidate Azure Key Vault Secrets",o={id:"Features/Security/auto-invalidate-secrets",title:"Automatically Invalidate Azure Key Vault Secrets",description:"The Arcus.BackgroundJobs.KeyVault library provides a background job to automatically invalidate cached Azure Key Vault secrets from an ICachedSecretProvider instance of your choice.",source:"@site/versioned_docs/version-v0.1/02-Features/02-Security/auto-invalidate-secrets.md",sourceDirName:"02-Features/02-Security",slug:"/Features/Security/auto-invalidate-secrets",permalink:"/v0.1/Features/Security/auto-invalidate-secrets",draft:!1,unlisted:!1,editUrl:"https://github.com/arcus-azure/arcus.backgroundjobs/edit/master/docs/versioned_docs/version-v0.1/02-Features/02-Security/auto-invalidate-secrets.md",tags:[],version:"v0.1",frontMatter:{title:"Automatically Invalidate Azure Key Vault Secrets",layout:"default"},sidebar:"tutorialSidebar",previous:{title:"Securely Receive CloudEvents",permalink:"/v0.1/Features/General/receive-cloudevents-job"}},a={},u=[{value:"How does it work?",id:"how-does-it-work",level:2},{value:"Usage",id:"usage",level:2}];function l(e){const t={a:"a",code:"code",h1:"h1",h2:"h2",img:"img",li:"li",p:"p",pre:"pre",ul:"ul",...(0,i.R)(),...e.components};return(0,n.jsxs)(n.Fragment,{children:[(0,n.jsx)(t.h1,{id:"automatically-invalidate-azure-key-vault-secrets",children:"Automatically Invalidate Azure Key Vault Secrets"}),"\n",(0,n.jsxs)(t.p,{children:["The ",(0,n.jsx)(t.code,{children:"Arcus.BackgroundJobs.KeyVault"})," library provides a background job to automatically invalidate cached Azure Key Vault secrets from an ",(0,n.jsx)(t.code,{children:"ICachedSecretProvider"})," instance of your choice."]}),"\n",(0,n.jsx)(t.h2,{id:"how-does-it-work",children:"How does it work?"}),"\n",(0,n.jsx)("a",{href:"https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2Farcus-azure%2Farcus.backgroundjobs%2Fmaster%2Fdeploy%2Farm%2Fazure-key-vault-job.json",target:"_blank",children:(0,n.jsx)("img",{src:"https://azuredeploy.net/deploybutton.png"})}),"\n",(0,n.jsxs)(t.p,{children:["This automation works by subscribing on the ",(0,n.jsx)(t.code,{children:"SecretNewVersionCreated"})," event of an Azure Key Vault resource and placing those events on a Azure Service Bus Topic; which we process in our background job."]}),"\n",(0,n.jsx)(t.p,{children:(0,n.jsx)(t.img,{alt:"Automatically Invalidate Azure Key Vault Secrets",src:r(6163).A+"",width:"600",height:"196"})}),"\n",(0,n.jsx)(t.p,{children:"To make this automation operational, following Azure Resources has to be used:"}),"\n",(0,n.jsxs)(t.ul,{children:["\n",(0,n.jsx)(t.li,{children:"Azure Key Vault instance"}),"\n",(0,n.jsx)(t.li,{children:"Azure Service Bus Topic"}),"\n",(0,n.jsxs)(t.li,{children:["Azure Event Grid subscription for ",(0,n.jsx)(t.code,{children:"SecretNewVersionCreated"})," events that are sent to the Azure Service Bus Topic"]}),"\n"]}),"\n",(0,n.jsx)(t.h2,{id:"usage",children:"Usage"}),"\n",(0,n.jsxs)(t.p,{children:["Our background job has to be configured in ",(0,n.jsx)(t.code,{children:"ConfigureServices"})," method:"]}),"\n",(0,n.jsx)(t.pre,{children:(0,n.jsx)(t.code,{className:"language-csharp",children:"using Arcus.Security.Core;\nusing Arcus.Security.Core.Caching;\nusing Microsoft.Extensions.DependencyInjection;\n\npublic class Startup\n{\n    public void ConfigureServices(IServiceCollection services)\n    {\n        // An 'ISecretProvider' implementation (see: https://security.arcus-azure.net/) to access the Azure Service Bus Topic resource;\n        //     this will get the 'serviceBusTopicConnectionStringSecretKey' string (configured below) and has to retrieve the connection string for the topic.\n        services.AddSingleton<ISecretProvider>(serviceProvider => ...);\n\n        // An `ICachedSecretProvider` implementation which secret keys will automatically be invalidated.\n        services.AddSingleton<ICachedSecretProvider>(serviceProvider => new CachedSecretProvider(mySecretProvider));
1\n\n        services.AddAutoInvalidateKeyVaultSecretBackgroundJob(\n            // Prefix of the Azure Service Bus Topic subscription;\n            //    this allows the background jobs to support applications that are running multiple instances, processing the same type of events, without conflicting subscription names.\n            subscriptionNamePrefix: \"MyPrefix\"\n\n            // Connection string secret key to a Azure Service Bus Topic.\n            serviceBusTopicConnectionStringSecretKey: \"MySecretKeyToServiceBusTopicConnectionString\");\n    }\n}\n"})}),"\n",(0,n.jsx)(t.p,{children:(0,n.jsx)(t.a,{href:"/",children:"\u2190 back"})})]})}function d(e={}){const{wrapper:t}={...(0,i.R)(),...e.components};return t?(0,n.jsx)(t,{...e,children:(0,n.jsx)(l,{...e})}):l(e)}},6163:(e,t,r)=>{r.d(t,{A:()=>n});const n=r.p+"assets/images/Azure-Key-Vault-Job-4379ac4e4bc2ed9b817b6ad5465b6dc8.png"},7468:(e,t,r)=>{r.d(t,{R:()=>c,x:()=>o});var n=r(758);const i={},s=n.createContext(i);function c(e){const t=n.useContext(s);return n.useMemo((function(){return"function"==typeof e?e(t):{...t,...e}}),[t,e])}function o(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:c(e.components),n.createElement(s.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.