Illustrative only - not an engagement finding
Build Files Contain a Reusable Service Key
Critical
See where this finding applies on the diagrams: delivery zone [planned] · CP7 workload identity federation
Illustrative only - not an engagement finding
Build Files Contain a Reusable Service Key
- Business summary
- A service key committed to deployment source or copied into build output remains recoverable from history and artifacts even after the latest file is cleaned up.
- Assessment profile
- Expected fix Verification
-
-
Expected fix Revoke and investigate exposure Credential owner and Azure Monitor logs: Revoke and rotate the value, then review its known exposure window for unauthorized use.Verification Reject the old value The revoked credential no longer authenticates, and the log review covers its full exposure window.
-
Expected fix Purge every retained copy Azure DevOps repository, artifacts, caches and deployment output: Remove the credential from current and historical material.Verification Find no surviving copy Secret scans of current files, history, artifacts, caches and deployment output return no match.
-
Expected fix Use a least-privilege workload identity Container Apps managed identity and Entra ID role assignments: Grant only the service roles the workload requires.Verification Enforce the approved role boundary The workload operates through managed identity and cannot perform operations outside its approved roles.
-
Expected fix Remove stored-key fallback Application code and App Configuration: Remove settings and fallback paths that still accept the reusable key.Verification Run without a stored credential The workload completes its approved work with no stored-key configuration or fallback path.
-
Expected fix Gate merges and releases on scanning Azure DevOps validation and release pipelines [planned]: Block current files, history or generated artifacts that contain credentials.Verification Block a planted secret A controlled test credential stops both merge and release.
-