【问题标题】:What would be the best practice to update the connection string from Key vault secret at runtime in mvc.net 4.xx在 mvc.net 4.xx 运行时从 Key Vault 机密更新连接字符串的最佳做法是什么
【发布时间】:2022-11-04 20:46:58
【问题描述】:

我想先提一下。我浏览了其他博客以找到答案,但我无法得到我正在寻找的问题的明确答案。

我在运行时从 Azure AD 获取存储连接字符串的 Key Vault 机密。我当前的程序具有硬编码的连接字符串,但它必须更改并且需要从 keyvault 机密更新。我能够以编程方式从 Azure 获取连接字符串。关键是我应该如何在配置文件中更新,以便每个应用程序只运行一次。

我的问题的目的是了解在运行时更新连接字符串的最佳做法以及如何做到这一点。正如我目前提到的,它在 webconfig 文件中是硬编码的,因此在不干扰 webconfig 文件中更新它的大部分代码的情况下,这对我来说是有好处的,但是,如果这不是一个好主意,那么有什么替代方案呢? 如果提供基于 ASP.Net MVC 4.xx 将受到高度赞赏的代码示例,我正在使用 ASP.Net MVC 4.8 。

在 MVC 中获取秘密的代码。假设秘密已被创建。

 public string ViewDataWithKeyVault()
    {

        var AzureKeyVaultName = "MyDbConnectionString";//get this from app settings. You can pass it as param to this method

        var secretClient = new SecretClient(new Uri($"https://{AzureKeyVaultName}.vault.azure.net/"), new DefaultAzureCredential());
        var secretVaults = secretClient.GetPropertiesOfSecrets().AsPages().ToList();

        var listName = new List<string>();
        string keyVaultName = "";
        foreach (var sV in secretVaults)
        {
            var keyVaultProp = sV.Values;
            foreach (var prop in keyVaultProp)
            {
                listName.Add(prop.Name);
                if (prop.Name.ToLower().Contains("mydb"))
                {
                    keyVaultName = prop.Name;
                }
            }
        }

        var sec = secretClient.GetSecret(keyVaultName);
        var connstring = sec.Value.ToString();
        return connstring;
    }

谢谢

【问题讨论】:

    标签: asp.net-mvc-4 azure-devops azure-keyvault


    【解决方案1】:

    检查以下解决方法以从 Azure KeyVault 读取连接字符串。 我已将Connection string 存储在Azure Secret 中,并将秘密设置在Azure App Configuration Section 中,并使用MVC 中的键值检索相同的内容

    • 在Azure Portal 中,创建一个Azure Key Vault。 提供所需信息并单击Review + create。

    • 在 Azure Key Vault 中,创建机密并复制Secret Identifier备查

    • 我们需要授予访问权限以检索机密。 Azure KeyVault => Access Policies => 创建 => 选择 Get,List 并点击 Review + create 对于主体,使用 Azure App Service 的名称搜索并选择

    • 在Visual Studio中=>右键单击项目文件夹=>点击Add=>Connected Service=>Add a service dependency=>添加Azure Key Vault

    • 登录Azure Account 并选择您在前面的步骤中创建的Subscription 和Azure Key Vault。

    • 配置 Key Vault 后,您的 web.config 将添加新设置。

    Web.config文件

      <configSections>
        <section name="configBuilders" type="System.Configuration.ConfigurationBuildersSection, System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a" restartOnExternalChanges="false" requirePermission="false" />
      </configSections>
      <configBuilders>
        <builders>
          <add name="AzureKeyVault"
                vaultName="dotnetthoughts"
                type="Microsoft.Configuration.ConfigurationBuilders.AzureKeyVaultConfigBuilder, Microsoft.Configuration.ConfigurationBuilders.Azure, Version=1.0.0.0, Culture=neutral"
                vaultUri="https://dotnetthoughts.vault.azure.net" />
        </builders>
      </configBuilders>
      <connectionStrings>
        <add name="MYconn" connectionString="Gets the value from Azure KeyVault" providerName="System.Data.SqlClient" />
      </connectionStrings>
    
    • 在 Azure 应用服务中,创建一个与 web.config 中同名的新连接字符串设置。将 Uri 替换为来自 KeyVault Secret 的 Secret Identifier
    Key - MYconn
    Value - @Microsoft.KeyVault(SecretUri=Uri)
    

    在HomeController 中,添加以下代码以获取连接字符串

     public ActionResult Index()
            {
                var conn = ConfigurationManager.ConnectionStrings["MYconn"];        
                ViewBag.myConnectionstring = conn;
                return View();
            }
    

    索引.cshtml

    <h2> @ViewBag.myConnectionstring</h2>
    

    【讨论】:

      猜你喜欢
      • 2010-10-12
      • 1970-01-01
      • 2019-08-11
      • 2011-05-10
      • 2017-05-22
      • 1970-01-01
      • 1970-01-01
      • 2015-09-16
      • 1970-01-01
      相关资源
      最近更新 更多