Skip to main content
Table of Contents
Print

Rotate eDig365 Reporter container registry credentials

Use this procedure to replace the pull-only token that eDig365 Reporter uses to retrieve its container image. It supports the eDig365 publisher registry and a customer-managed Docker Registry v2 or compatible OCI registry.

The procedure creates a new version of the existing container-registry-password secret in the application’s Azure Key Vault, refreshes the App Service Key Vault reference, restarts the application, and verifies health. It doesn’t change the registry username, registry server, repository, image tag or digest, network settings, or application image.

Before you begin

Prepare the following:

  • A newly issued, pull-only registry token for the existing registry username.
  • The eDig365 Reporter deployment subscription, resource group, App Service, and Key Vault names.
  • Azure portal access to the Key Vault and App Service.
  • The Key Vault Secrets Officer Azure role on the Key Vault or the container-registry-password secret. The role permits creating a new secret version without granting permission to manage Key Vault access.
  • Permission to restart the App Service. Contributor on the App Service or its resource group provides this permission.
  • Access to the Key Vault’s private endpoint when public network access is disabled. The portal secret operation uses the Key Vault data plane and must be performed from an authorized network.
  • Network access to the application’s health endpoint. For private ingress, run the procedure from an authorized network.

Ask a Key Vault administrator to assign the required role before beginning. Key Vault Contributor alone doesn’t permit creating or changing secret values. Keep the old token active until this procedure completes successfully. Don’t enter the replacement token in source files, command history, deployment parameters, support tickets, or logs.

Rotate the token

  1. Obtain a new pull-only token in the registry. Keep the existing registry username, server, repository, and image reference unchanged.
  2. In the Azure portal, open the deployment resource group, then select the application Key Vault.
  3. Select Objects > Secrets, then select container-registry-password.
  4. Select New Version. If your portal view instead shows Generate/Import, select it and use the existing secret name.
  5. Set Upload options to Manual, enter the replacement token as the secret value, and select Create. Don’t change the secret name.
  6. Open the eDig365 Reporter App Service. Select Settings > Environment variables, then select Refresh to refresh Key Vault references. If Refresh isn’t available, select Save without changing any settings.
  7. Select Overview > Restart, then confirm the restart.

Verify the result

After the restart, request https://<app-service-name>.azurewebsites.net/api/info/health and confirm that it returns HTTP 200. For private ingress, request the endpoint from an authorized network.

In the App Service, open Settings > Environment variables and confirm that the Key Vault reference for DOCKER_REGISTRY_SERVER_PASSWORD is healthy. Review the configured container image and confirm that its registry server, repository, tag, or digest didn’t change during the rotation. Record the new secret version, image reference, health endpoint, date, and operator in your change record.

Review App Service container logs for an image-pull or startup failure if the health check takes longer than expected.

After successful validation, revoke the old registry token according to your registry’s credential management procedure.

Troubleshoot

Symptom First checks
Can’t create a new secret version Confirm that you have the Key Vault Secrets Officer role at the Key Vault or secret scope. Key Vault Contributor doesn’t grant access to secret values.
Key Vault update fails with network access denied The vault uses private networking. Access the portal from a network that can reach the Key Vault private endpoint, or ask an authorized operator to create the new version.
The App Service reference isn’t healthy Select Refresh under Environment variables, then restart the App Service. Check that DOCKER_REGISTRY_SERVER_PASSWORD still refers to the expected Key Vault secret.
Health check doesn’t succeed Check App Service container logs, Key Vault reference status, registry DNS and TLS, token permissions, and outbound routing. For private ingress, run the check from an authorized network.
Container image changed Stop and investigate before revoking the old token. Credential rotation must not change the registry server, repository, tag, or digest.
A later deployment can’t pull the image Confirm that the active container-registry-password secret version contains a valid current pull-only token, then restart the App Service after correcting it.

Related documentation