- Reference
- Version · 6.0
- Change Automation Reference
liquibase-azure-key-vault-url
Last updated: September 29, 2026
liquibase.azure.keyVault.url is a global parameter for the Liquibase Azure extension. It sets the Azure Key Vault that Liquibase reads secrets from by default, so a vault reference in your configuration can leave its vault URL out. This parameter has no default value. When it is not set, every vault reference must name its own vault inline.
Note: An inline vault URL always wins. A reference that supplies its own vault URL uses that vault even when this parameter is set, so you can point one value at a different vault without changing this setting.
Uses
A vault reference names the vault it reads from, in the form azure-key-vault-secret,<vault-url>,<secret-name>. When most of your references point at the same vault, repeating that URL on each one adds noise and gives you more than one place to edit when the vault changes.
Setting liquibase.azure.keyVault.url gives those references a default. Leave the vault URL segment empty and Liquibase substitutes this value, so azure-key-vault-secret,,my-database-password resolves against your default vault. The same applies to key and certificate references, which use the azure-key-vault-key and azure-key-vault-cert prefixes.
Liquibase reports a clear error when a reference leaves the vault URL empty and no default is configured, so a missing value fails fast rather than resolving against the wrong vault.
Syntax
You can set this parameter in the following ways:
Option | Syntax |
Liquibase properties file (defaults file) |
|
JVM system property (JAVA_OPTS Environment Variable) | Unix: |
Liquibase Environment Variables |
|