Azure Keyvault Py

作者 microsoft354361d83247MIT收錄於 2026年10月8日更新於 2026年10月8日

Azure Key Vault SDK for Python. Use for secrets, keys, and certificates management with secure storage. Triggers: "key vault", "SecretClient", "KeyClient", "CertificateClient", "secrets", "encryption keys".

AI 產生的概覽

使用 Azure Key Vault Python SDK 管理祕密、金鑰與憑證的說明。

功能
此技能提供使用 Azure Key Vault Python SDK 的指引與程式碼範例。內容涵蓋 SecretClient、KeyClient、CryptographyClient 與 CertificateClient 的用戶端設定,以及設定與取得祕密、建立 RSA 與 EC 金鑰、加密、解密、簽章、驗證與管理憑證等操作。它也說明了使用 DefaultAzureCredential 進行驗證、非同步用戶端、錯誤處理與最佳做法。
適用情境
當你撰寫在 Azure Key Vault 中儲存或取得祕密、管理密碼編譯金鑰或處理憑證的 Python 程式碼時,可使用此技能。它適合需要 Azure Key Vault SDK 設定模式、操作範例或驗證指引的開發人員。
執行需求
需要 Python 以及 azure-keyvault-secrets、azure-keyvault-keys、azure-keyvault-certificates 與 azure-identity 套件。需要 Azure Key Vault URL 與 Azure 認證(例如 DefaultAzureCredential 或受控識別),並需要連線至 Azure 的網路存取。不包含指令碼,僅為指示文件。

Azure Key Vault SDK for Python

Secure storage and management for secrets, cryptographic keys, and certificates.

Installation

bash
# Secretspip install azure-keyvault-secrets azure-identity
# Keys (cryptographic operations)pip install azure-keyvault-keys azure-identity
# Certificatespip install azure-keyvault-certificates azure-identity
# Allpip install azure-keyvault-secrets azure-keyvault-keys azure-keyvault-certificates azure-identity

Environment Variables

bash
AZURE_KEYVAULT_URL=https://<vault-name>.vault.azure.net/  # Required for all auth methodsAZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production

Authentication & Lifecycle

🔑 Two rules apply to every code sample below:

  1. Prefer DefaultAzureCredential. It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.
    • Local dev: DefaultAzureCredential works as-is.
    • Production: set AZURE_TOKEN_CREDENTIALS=prod (or AZURE_TOKEN_CREDENTIALS=<specific_credential>) to constrain the credential chain to production-safe credentials.
  2. Wrap every client in a context manager so HTTP transports, sockets, and token caches are released deterministically:
    • Sync: with <Client>(...) as client:
    • Async: async with <Client>(...) as client: and async with DefaultAzureCredential() as credential: (from azure.identity.aio)

Snippets may abbreviate this setup, but production code should always follow both rules.

Secrets

SecretClient Setup

python
from azure.identity import DefaultAzureCredential, ManagedIdentityCredentialfrom azure.keyvault.secrets import SecretClient
# Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>credential = DefaultAzureCredential(require_envvar=True)# Or use a specific credential directly in production:# See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes# credential = ManagedIdentityCredential()vault_url = "https://<vault-name>.vault.azure.net/"
with SecretClient(vault_url=vault_url, credential=credential) as client:    # All secret operations go inside this block (see examples below)    ...

Secret Operations

python
# Set secretsecret = client.set_secret("database-password", "super-secret-value")print(f"Created: {secret.name}, version: {secret.properties.version}")
# Get secretsecret = client.get_secret("database-password")print(f"Value: {secret.value}")
# Get specific versionsecret = client.get_secret("database-password", version="abc123")
# List secrets (names only, not values)for secret_properties in client.list_properties_of_secrets():    print(f"Secret: {secret_properties.name}")
# List versionsfor version in client.list_properties_of_secret_versions("database-password"):    print(f"Version: {version.version}, Created: {version.created_on}")
# Delete secret (soft delete)poller = client.begin_delete_secret("database-password")deleted_secret = poller.result()
# Purge (permanent delete, if soft-delete enabled)client.purge_deleted_secret("database-password")
# Recover deleted secretclient.begin_recover_deleted_secret("database-password").result()

Keys

KeyClient Setup

python
from azure.identity import DefaultAzureCredentialfrom azure.keyvault.keys import KeyClient
credential = DefaultAzureCredential()vault_url = "https://<vault-name>.vault.azure.net/"
with KeyClient(vault_url=vault_url, credential=credential) as client:    # All key operations go inside this block (see examples below)    ...

Key Operations

python
from azure.keyvault.keys import KeyType
# Create RSA keyrsa_key = client.create_rsa_key("rsa-key", size=2048)
# Create EC keyec_key = client.create_ec_key("ec-key", curve="P-256")
# Get keykey = client.get_key("rsa-key")print(f"Key type: {key.key_type}")
# List keysfor key_properties in client.list_properties_of_keys():    print(f"Key: {key_properties.name}")
# Delete keypoller = client.begin_delete_key("rsa-key")deleted_key = poller.result()

Cryptographic Operations

python
from azure.keyvault.keys.crypto import CryptographyClient, EncryptionAlgorithm
# Get crypto client for a specific key# crypto_client = CryptographyClient(key, credential=credential)# Or from key IDwith CryptographyClient(    "https://<vault>.vault.azure.net/keys/<key-name>/<version>",    credential=credential) as crypto_client:    # Encrypt    plaintext = b"Hello, Key Vault!"    result = crypto_client.encrypt(EncryptionAlgorithm.rsa_oaep, plaintext)    ciphertext = result.ciphertext
    # Decrypt    result = crypto_client.decrypt(EncryptionAlgorithm.rsa_oaep, ciphertext)    decrypted = result.plaintext
    # Sign    from azure.keyvault.keys.crypto import SignatureAlgorithm    import hashlib
    digest = hashlib.sha256(b"data to sign").digest()    result = crypto_client.sign(SignatureAlgorithm.rs256, digest)    signature = result.signature
    # Verify    result = crypto_client.verify(SignatureAlgorithm.rs256, digest, signature)    print(f"Valid: {result.is_valid}")

Certificates

CertificateClient Setup

python
from azure.identity import DefaultAzureCredentialfrom azure.keyvault.certificates import CertificateClient, CertificatePolicy
credential = DefaultAzureCredential()vault_url = "https://<vault-name>.vault.azure.net/"
with CertificateClient(vault_url=vault_url, credential=credential) as client:    # All certificate operations go inside this block (see examples below)    ...

Certificate Operations

python
# Create self-signed certificatepolicy = CertificatePolicy.get_default()poller = client.begin_create_certificate("my-cert", policy=policy)certificate = poller.result()
# Get certificatecertificate = client.get_certificate("my-cert")print(f"Thumbprint: {certificate.properties.x509_thumbprint.hex()}")
# Get certificate with private key (as secret)from azure.keyvault.secrets import SecretClientwith SecretClient(vault_url=vault_url, credential=credential) as secret_client:    cert_secret = secret_client.get_secret("my-cert")    # cert_secret.value contains PEM or PKCS12
# List certificatesfor cert in client.list_properties_of_certificates():    print(f"Certificate: {cert.name}")
# Delete certificatepoller = client.begin_delete_certificate("my-cert")deleted = poller.result()

Client Types Table

ClientPackagePurpose
SecretClientazure-keyvault-secretsStore/retrieve secrets
KeyClientazure-keyvault-keysManage cryptographic keys
CryptographyClientazure-keyvault-keysEncrypt/decrypt/sign/verify
CertificateClientazure-keyvault-certificatesManage certificates

Async Clients

python
from azure.identity.aio import DefaultAzureCredentialfrom azure.keyvault.secrets.aio import SecretClient
async def get_secret():    async with DefaultAzureCredential() as credential:        async with SecretClient(vault_url=vault_url, credential=credential) as client:            secret = await client.get_secret("my-secret")            print(secret.value)
import asyncioasyncio.run(get_secret())

Error Handling

python
from azure.core.exceptions import ResourceNotFoundError, HttpResponseError
try:    secret = client.get_secret("nonexistent")except ResourceNotFoundError:    print("Secret not found")except HttpResponseError as e:    if e.status_code == 403:        print("Access denied - check RBAC permissions")    raise

Best Practices

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose one mode per module.
  2. Always use context managers for clients and async credentials. Wrap every client in with Client(...) as client: (sync) or async with Client(...) as client: (async). For async DefaultAzureCredential from azure.identity.aio, also use async with credential: so tokens and transports are cleaned up.
  3. Use DefaultAzureCredential for code that runs locally. Use a specific token credential for code that runs in Azure.
  4. Use managed identity in Azure-hosted applications
  5. Enable soft-delete for recovery (enabled by default)
  6. Use RBAC over access policies for fine-grained control
  7. Rotate secrets regularly using versioning
  8. Use Key Vault references in App Service/Functions config
  9. Cache secrets appropriately to reduce API calls
  10. Use async clients for high-throughput scenarios

Reference Files

FileContents
references/capabilities.md [blocked]Additional non-hero capabilities, operation-group coverage, and production checklists.
references/non-hero-scenarios.md [blocked]Dedicated non-hero examples for secondary/advanced scenarios.

來源與署名

來源:microsoft/skills位於.github/plugins/azure-sdk-python/skills/azure-keyvault-py提交354361d

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架