Skip to main content

Secrets

Secrets consumed directly by apps (both for development and production) are stored in Azure Key Vault.

Secrets consumed by humans (cloud logins) are stored in 1Password.

Azure Key Vault

Granting Access

Create a User

  1. In the Azure Portal, go to Microsoft Entra ID.

  2. Expand Manage -> Users

  3. Click on New user and either (recommended) create an internal user or invite an external one.

  4. Add the user to the relevant group to grant them the relevant permissions.

(Deprecated) Grant Secret Reader Roles

info

This is now deprecated in favor of adding roles to groups, and users to groups.

  1. Navigate to the vault you want to grant access to. (eg. glhf-key-vault)

  2. Click on Access control (IAM) -> Add role assignment.

  3. Grant the user access to Key Vault Secrets User

  4. Click on Access policies

  5. Click Create and grant the user permissions from a template.

1Password

Granting Access

Invite a User

  1. Go to 1Password -> People.

  2. Click Invite People

Grant Access

  1. Go to 1Password -> People.

  2. Click on the user you wish to edit.

  3. Click Manage next to Vaults and grant access to a vault.