Showing posts with label KeyVault. Show all posts
Showing posts with label KeyVault. Show all posts

17 March, 2020

Azure key vault with .net framework 4.8



Azure Key Vault  With .Net Framework 4.8


I was asked to migrate asp.net MVC 5 web application to Azure and I were looking for the key vault integrations and access all the secrete out from there.

Azure Key Vault Config Builder


Configuration builders for ASP.NET are new in .NET Framework >=4.7.1 and .NET Core >=2.0 and allow for pulling settings from one or many sources. Config builders support a number of different sources like user secrets, environment variables and Azure Key Vault and also you can create your own config builder, to pull in configuration from your own configuration management system.

Here I am going to demo Key Vault integrations with Asp.net MVC(download .net framework 4.8). You will find that it's magical, without code, changes how your app can read secretes from the key vault. Just you have to do the few configurations in your web config file.

Prerequisite:
Following resource are required to run/complete this demo
·        Azure subscription
o   Create an Azure web app
o   Create a key vault resource
§  Add a couple of secretes
·        Visual studio 2019 ready to use on your machine
·        .Net Framework 4.8 installed

Configuration Details

I have ready code/running for you that you can download code from Git Hub

The NuGet package  “Microsoft.Configuration.ConfigurationBuilders.Azure” version 2.0.0. It will facilitate to access the give secretes from the azure key vault. when you will install this package it will install all the required other packages.


When you will install it will make the following changes in your web.config file. you need to update your key vault name here.

  <add name="AzureKeyVault"  vaultName="demo-dotnet47-kv
  • Above highlighted key vault name you need to replace with yours once.
if you want to render and read connection string to decore with

<connectionStrings configBuilders="AzureKeyVault">

if you want to render your app setting from key vault so decorate with same like connection sting you can see the highlighted in green color

You need to add the empty connection string and add secrete with the same name, see the highlighted items in orange color

web.config



Let's see the Key Vault and Secretes

If you are new to the azure key vault please visit this tutorial so learn around and provision steps

here is the one that we have used in this demo. 
If you are running the app from your local machine so make sure that you logged with the same principle(user Id) that you added under the azure key vault access policy otherwise your app will be unable to access the secretes

if you are running you this demo after publishing the azure web app, make sure that you have added Managed Identity on and you have granted access to it under key vault access policy.

in this demo we are trying access only below highlighted secretes from key vault no all because of the default config builder behavior mode="strict". if you want to read/add all the secrets then set up the mode = "Greedy"  in the above config file 

  <add name="AzureKeyVault" mode="Greedy" vaultName="demo-dotnet47-kv" 


azure key vault


Key Vault Access Policy Settings

key-vault-access-policy

Managed Identity setup for your web app:


web-app-manged-identity


Asp.net MVC 5 Code and Neuget Packages Details


once you will download this code from Git Hub, you will notice the following changes

NuGet Packages:
config-builder-nuget-packages.JPG


Code demo to read secretes:

read-secretes-value


Show these values on view: not best practices its a just for the demo and with demo secretes.



show-secretes-over-view.JPG



Finally, we have done with all the required changes so let's run the app and see the result.

A result from the local machine 

Before running this app lets do the last thing. Open Azure CLI(CMD) and run the command "az login" because managed Identity use azure CLI to get generate token to connect with Azure resources.


AzureKeyVaultConfigBuilder demo local

Let's have demo app running over the azure

azure-app-demo.JPG

11 December, 2019

Azure Data Load (ETL) Process using Azure Functions Step by Step Example

Data Load (ETL) Process using Azure Functions


Azure Functions 

are serverless and are a great solution for processing data, integrating systems, working with the internet-of-things (IoT), and building simple APIs and microservices. Consider Functions for tasks like image or order processing, file maintenance, or for any tasks that you want to run on a schedule.

Here we are talking about ETL process implementation using Azure Functions, even though Azure Data Factory is out there but if you are a c# developer you will love it. You can leverage all the benefits of the App Service Plan and/or Consumption Plan(Pay As you Go) along with Event-Driven Process and Programming Model

Azure Durable Function

Durable Function is an extension of Azure Function that lets you write stateful functions in a serverless compute environment. It allows you to define stateful workflows by writing orchestrator functions and stateful entities by writing entity/Activity functions using the Azure Functions programming model. All other things like state management, checkpoints, and restarts for you, will be taken care of by azure durable function engine and allowing you to focus on your business logic.

The primary requirement is the reader should be familiar  with Azure function and durable functions

Business Requirement

 We have CSV file dropped into the azure blob storage/container and that file should be process and data saved into the Azure SQL Server.

Design and Architecture

  • Azure Function: It's a blob trigger function and starter for the data load process.
  • Azure Durable Functions - Orchestrator: It's an orchestrator function that will manage the workflow/data flow activities function and all the executions 
  • Azure Durable Functions - Activity: An azure function that will actually process the CSV data and will insert into the azure SQL database
  • Azure SQL Server: will be in used to keep processed data
  • SendGrid: will be used to send emails and acknowledgment on process completion
  • Application Insights: can be used to logging the exception event etc..
work flow

Development Environment Setup:

  1.  Visit MSDN for the step by step example  here is a link
  2.  Required NuGet package Microsoft.Azure.WebJobs.Extensions.DurableTask

Code and Example : 

Here is a list of code screenshots
Start Function: its a blob trigger azure function that will execute automatically once any CSV file will be dropped into the container "samples-workitems"

Start Function


Orchestrator Function : 

it will manage the life cycle of data workflow 
Orchestrator Function


Activity Functions
perform actual data manipulation and communication with the database.

Activity Functions


Solutions and NuGet pkg:
Solutions and NuGet pkg

Bonus Points: 

  1. Use Cunsputions Plans only if you are sure that you function execution time will no exceed 10minutes limit
  2. Use App Service Plan if need to configure vnet andother securtity and if your function will need more than 10 minutes to complete the task just you need to configure function time out in host.json
  3. Visit for more Application Patterns