Azure Static Web Apps settings
The backend API of a static site reads these. A write replaces the whole set, so a portal edit made at the same time is lost.
The backend API of a static site reads these. A write replaces the whole set, so a portal edit made at the same time is lost.
The connection
| What | This provider |
|---|---|
| Vendor | Microsoft Azure |
| Key | azure-static-web-apps-settings |
| Availability | available. You can connect it today. |
| Credential penv holds | azure-service-principal |
| Values read back | yes |
| Activation | immediate |
What it moves
| Direction | What it does |
|---|---|
import | Reads names and values out of the store into penv. |
export | Writes names and values from penv into the store. |
When a written value goes live
immediate. The running app sees a new value at once.
What happens to a name that exists
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
How you connect
You paste a credential you already hold. penv seals it and never shows it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
tenantId | Directory (tenant) ID | secret, masked here and sealed | yes | |
clientId | Application (client) ID | secret, masked here and sealed | yes | |
clientSecret | Client secret | secret, masked here and sealed | yes |
What the connection asks for
Fixed when you connect, and shared by every mapping on it.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
subscriptionId | Subscription ID | text | yes | no | The subscription the service principal has a role assignment on. |
resourceGroup | Resource group | text | yes | no | The group the target resource sits in. One connection covers one group. |
What a mapping asks for
Answered once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
siteName | Static site | text | yes | no | The site whose backend API reads these settings. |
environmentName | Environment | text | no | yes | Leave empty for production. Azure copies these settings to staging too. |
Permissions it needs
penv probes for these when it verifies the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
Microsoft.Web/staticSites/listAppSettings/action | every direction | yes | Preview cannot read the site's settings. |
Microsoft.Web/staticSites/config/write | export | yes | Export cannot write anything. |
Microsoft.Web/staticSites/Read | every direction | no | Verify cannot confirm the credential reaches this resource group. |
Related
Azure App Service app settings
App Service and Functions read these as environment variables. A write replaces the whole set, so a portal edit made at the same time is lost.
Azure Container Apps
Secrets on a container app. A write replaces the whole set, so a concurrent portal edit is lost. A revision holds its old value until you restart or redeploy, and a referenced secret is never pruned.