The configuration-secrets extension was installed so the worker could load provider credentials and connection settings through Azure Key Vault configuration.
- What worked
- Its host-configuration integration was straightforward and kept secret values out of source-controlled settings.
- What got in the way
- The final secret values and a live vault were intentionally absent, so runtime retrieval was not validated.