KEEP CREDENTIALS OUT OF CODE: Tips & Tricks for managing secrets during development

Your code needs credentials to authenticate to cloud services, but you want to limit the visibility of those credentials as much as possible. Ideally, they never appear on a developer’s workstation or get checked-in to source control. Azure Key Vault can store credentials securely so they aren’t in your code, but to retrieve them you need to authenticate to Azure Key Vault. To authenticate to Key Vault, you need a credential! A classic bootstrap problem. Through the magic of Azure and Azure AD, Managed Service Identity provides a “bootstrap identity” that makes it much simpler to get things started. This session will introduce MSI and provide steps for configuring the service and securing your code.

200 - Intermediate
.NET Cloud Security
Room 121