Set up or rotate a show-specific password gate for AIPodcasting studio routes. Use when adding a new show or changing access for `/content/episodes/*?show=SHOW_NAME`, so `PASSWORD_SHOW_SHOWNAME` is stored in Key Vault and app settings use Key Vault references.
インストール
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
Set up or rotate a show-specific password gate for AIPodcasting studio routes. Use when adding a new show or changing access for `/content/episodes/*?show=SHOW_NAME`, so `PASSWORD_SHOW_SHOWNAME` is stored in Key Vault and app settings use Key Vault references.
Show Password Setup
Overview
Provision a show-specific password for the AIPodcasting frontend by setting the correct
PASSWORD_SHOW_<SHOWNAME> env var through Key Vault-backed app settings. This mirrors the middleware-based
password protection flow used by the studios.
Workflow
Collect inputs
Show name (should match the ?show= value used in URLs; typically the WIN podcast_name).
Password string.
Azure resource group (optional; auto-detected if possible).
Key Vault name (defaults to kv-shared-repos).
Normalize the show ID
Uppercase.
Non-alphanumeric => _.
Collapse multiple _.
Trim leading/trailing _.
Set Key Vault secret
Secret name pattern: aipodcasting-app--password-show-<show-slug>.
Write password value to Key Vault (kv-shared-repos by default).
Set Azure env var to Key Vault reference
App: aipodcasting-app.
Var: PASSWORD_SHOW_<SHOWNAME>.
Value format:
@Microsoft.KeyVault(SecretUri=https://<vault>.vault.azure.net/secrets/<secret-name>/)
Use Azure CLI (az webapp config appsettings set).
Update local mapping + bootstrap .env
Add/replace mapping in scripts/local/secrets/keyvault_env_map.env.
Mirror mapping in scripts/local/secrets/keyvault_env_map.env.example for repo contract consistency.
Regenerate local .env via scripts/local/secrets/bootstrap_local_env_from_keyvault.sh.
Keep secret values out of git.
Confirm
Echo env var name, Key Vault secret name, and target app.