Skip Key Vault secret refs in the container app until Stripe keys are set - #416
Conversation
Gemini PR ReviewReviewed commit:
|
03c7336 to
b0f712b
Compare
Gemini PR ReviewReviewed commit:
|
b0f712b to
362bfdf
Compare
|
/gemini review |
2 similar comments
|
/gemini review |
|
/gemini review |
Gemini PR ReviewReviewed commit:
This result blocks merge. Push a fix and comment |
|
/gemini dispute
|
|
/gemini review |
Gemini PR ReviewReviewed commit:
|
The Azure deploy has never completed. Infra provisions, but the Container App revision fails with "unable to fetch secret 'stripe-secret-key' using Managed identity" because it always references the three Stripe secrets in Key Vault, even when no real Stripe keys were supplied (Key Vault just holds the placeholder 'unset').
This adds a
stripeEnabledflag to the container app module.main.bicepsets it to true only when bothstripeSecretKeyandstripeWebhookSecretare non-empty. While it is false, the app gets no Key Vault secret references and no STRIPE_* env vars, so it starts in simulation mode (the existing behavior when no keys are set). Once the real keys are added as repo secrets and the deploy re-runs, the references come back.Checked:
az bicep buildpasses. The identity, role assignment, and secrets in Key Vault all look correct, so I could not find why the Key Vault read fails; this change takes it out of the first-deploy path. If it still fails after real keys are set, that needs a look at the vault's diagnostic logs.Not changed: Key Vault module, workflow, parameters.
Thanks, Gerard Recinto