End-to-end automated infrastructure for rotating Azure AD app credentials, storing them in Key Vault, and alerting on failures — deployed via CI/CD with zero standing secrets.
flowchart TD
GH["GitHub Actions\nOIDC Auth + Terraform Plan/Apply"]
GH -->|OIDC Login| AZ["Azure"]
subgraph AZ_Resources["Azure Resources"]
APP["App Registration\n+ Service Principal"]
KV["Key Vault\nRBAC Mode"]
FUNC["Azure Function\nPython 3.11\nTimer Trigger"]
LOG["Log Analytics\nWorkspace"]
EG["Event Grid\nSubscription"]
MON["Monitor Alert\n+ Action Group"]
POL["Azure Policy\nEnforce KV RBAC"]
APP -->|Credentials stored in| KV
FUNC -->|Rotates credentials| APP
FUNC -->|Writes new secret| KV
KV -->|Diagnostic logs| LOG
KV -->|Near-expiry event| EG
EG -->|Triggers| FUNC
FUNC -->|On failure| MON
MON -->|Email alert| EMAIL["Admin Email"]
POL -->|Enforces RBAC on| KV
end