• Task
  • Version · 6.0
  • Create

Use Azure Key Vault secrets with Liquibase

Last updated: September 29, 2026

Store sensitive Liquibase configuration values, such as database passwords, in Azure Key Vault and reference them from your Liquibase configuration. Liquibase resolves each reference at command time using your Azure environment's credentials, so no secret values appear in your configuration files or version control. This feature requires a Liquibase Secure license and is included in the Liquibase Azure extension, which ships with Liquibase Secure.

Procedure

1

Grant your Azure identity access to the vault

2

Provide Azure credentials

3

Reference vault items in your Liquibase configuration

liquibase.command.password=azure-key-vault-secret,https://your_vault_name.vault.azure.net,your_secret_name,your_version_id
liquibase.azure.keyVault.url=https://your_vault_name.vault.azure.net
liquibase.command.password=azure-key-vault-secret,,your_secret_name
your.property=azure-key-vault-key,https://your_vault_name.vault.azure.net,your_key_name
your.other.property=azure-key-vault-cert,https://your_vault_name.vault.azure.net,your_certificate_name
4

Verify the resolution

loading
LIQUIBASE_COMMAND_PASSWORD resolved to an Azure Key Vault Secrets secret.

Troubleshooting

Failed to retrieve secret from vault

Failed to retrieve secret from vault 'https://your_vault_name.vault.azure.net'. Verify the RBAC role assignment (or legacy access policy) on the calling identity. (cause: HTTP 403)

Liquibase deliberately reports the same message whether the item is missing or access was denied, so that item names cannot leak into logs. The cause segment identifies the failure:

Cause

Meaning

HTTP 403

The identity authenticated but has no role assignment or access policy on the vault

HTTP 404

The item name is wrong or the item was deleted

UncheckedIOException

The vault URL is wrong or the vault host is unreachable

CredentialUnavailableException

No credentials found in the environment. Set the environment variables, run az login, or configure Managed Identity

Invalid Azure Key Vault Secrets reference

Invalid Azure Key Vault Secrets reference. Expected 'azure-key-vault-secret,<vault-url>,<name>[,<version>]' but found 2 comma-separated segment(s).

The reference has too few or too many comma-separated segments. Check for a missing segment or a stray comma.

Azure Key Vault Secrets requires a vault URL

The vault URL segment is empty and no default vault URL is configured. Add the URL inline or set liquibase.azure.keyVault.url.

Vault URL must be an https:// URL

The vault URL segment must start with https://. Only the scheme is validated, so vaults in sovereign and government clouds work with their native hostnames.

The reference is used literally as the password

If your database rejects the connection and the failure shows the full reference string as the attempted password, Liquibase never resolved the reference. This happens on Liquibase versions that do not include Azure Key Vault support. No warning is logged on those versions. Upgrade to Liquibase Secure 6.0 or later and confirm that liquibase --version lists internal/extensions/liquibase-azure.jar.

Requires the Liquibase Azure extension and a Liquibase Secure license

Add a valid Liquibase Secure license key to your configuration. Without a valid license the command fails with this error rather than continuing with the reference unresolved, so the value is never read from the vault.