- Task
- Version · 6.0
- Create
Use Azure Key Vault secrets with Liquibase
Last updated: September 29, 2026
Store sensitive Liquibase configuration values, such as database passwords, in Azure Key Vault and reference them from your Liquibase configuration. Liquibase resolves each reference at command time using your Azure environment's credentials, so no secret values appear in your configuration files or version control. This feature requires a Liquibase Secure license and is included in the Liquibase Azure extension, which ships with Liquibase Secure.
Procedure
Grant your Azure identity access to the vault
Provide Azure credentials
Reference vault items in your Liquibase configuration
liquibase.command.password=azure-key-vault-secret,https://your_vault_name.vault.azure.net,your_secret_name,your_version_idliquibase.azure.keyVault.url=https://your_vault_name.vault.azure.net
liquibase.command.password=azure-key-vault-secret,,your_secret_nameyour.property=azure-key-vault-key,https://your_vault_name.vault.azure.net,your_key_name
your.other.property=azure-key-vault-cert,https://your_vault_name.vault.azure.net,your_certificate_nameVerify the resolution
LIQUIBASE_COMMAND_PASSWORD resolved to an Azure Key Vault Secrets secret.Troubleshooting
Failed to retrieve secret from vault
Failed to retrieve secret from vault 'https://your_vault_name.vault.azure.net'. Verify the RBAC role assignment (or legacy access policy) on the calling identity. (cause: HTTP 403)Liquibase deliberately reports the same message whether the item is missing or access was denied, so that item names cannot leak into logs. The cause segment identifies the failure:
Cause | Meaning |
| The identity authenticated but has no role assignment or access policy on the vault |
| The item name is wrong or the item was deleted |
| The vault URL is wrong or the vault host is unreachable |
| No credentials found in the environment. Set the environment variables, run |
Invalid Azure Key Vault Secrets reference
Invalid Azure Key Vault Secrets reference. Expected 'azure-key-vault-secret,<vault-url>,<name>[,<version>]' but found 2 comma-separated segment(s).The reference has too few or too many comma-separated segments. Check for a missing segment or a stray comma.
Azure Key Vault Secrets requires a vault URL
The vault URL segment is empty and no default vault URL is configured. Add the URL inline or set liquibase.azure.keyVault.url.
Vault URL must be an https:// URL
The vault URL segment must start with https://. Only the scheme is validated, so vaults in sovereign and government clouds work with their native hostnames.
The reference is used literally as the password
If your database rejects the connection and the failure shows the full reference string as the attempted password, Liquibase never resolved the reference. This happens on Liquibase versions that do not include Azure Key Vault support. No warning is logged on those versions. Upgrade to Liquibase Secure 6.0 or later and confirm that liquibase --version lists internal/extensions/liquibase-azure.jar.
Requires the Liquibase Azure extension and a Liquibase Secure license
Add a valid Liquibase Secure license key to your configuration. Without a valid license the command fails with this error rather than continuing with the reference unresolved, so the value is never read from the vault.