• Reference
  • Version · 6.0
  • Change Automation Reference

liquibase-azure-key-vault-url

Last updated: September 29, 2026

liquibase.azure.keyVault.url is a global parameter for the Liquibase Azure extension. It sets the Azure Key Vault that Liquibase reads secrets from by default, so a vault reference in your configuration can leave its vault URL out. This parameter has no default value. When it is not set, every vault reference must name its own vault inline.

Note: An inline vault URL always wins. A reference that supplies its own vault URL uses that vault even when this parameter is set, so you can point one value at a different vault without changing this setting.

Uses

A vault reference names the vault it reads from, in the form azure-key-vault-secret,<vault-url>,<secret-name>. When most of your references point at the same vault, repeating that URL on each one adds noise and gives you more than one place to edit when the vault changes.

Setting liquibase.azure.keyVault.url gives those references a default. Leave the vault URL segment empty and Liquibase substitutes this value, so azure-key-vault-secret,,my-database-password resolves against your default vault. The same applies to key and certificate references, which use the azure-key-vault-key and azure-key-vault-cert prefixes.

Liquibase reports a clear error when a reference leaves the vault URL empty and no default is configured, so a missing value fails fast rather than resolving against the wrong vault.

Syntax

You can set this parameter in the following ways:

Option

Syntax

Liquibase properties file (defaults file)

liquibase.azure.keyVault.url=<vault-url>

JVM system property (JAVA_OPTS Environment Variable)

Unix:JAVA_OPTS=-Dliquibase.azure.keyVault.url=<vault-url>Windows:JAVA_OPTS=-D"liquibase.azure.keyVault.url"=<vault-url>

Liquibase Environment Variables

LIQUIBASE_AZURE_KEY_VAULT_URL=<vault-url>