Variable groups are the junk drawer of Azure DevOps: connection strings, API keys, feature flags, and one variable named TEMP_TOKEN_DO_NOT_USE from 2022. Because groups are linkable across pipelines, a secret added for one build quietly becomes readable by many.
How sprawl happens
- Groups linked 'temporarily' to unblock a build and never unlinked.
- Secrets stored as plain variables because someone needed to read them back.
- Cloned pipelines inheriting group links nobody re-evaluated.
- Retired integrations whose variables linger because deletion feels risky.
Cleaning up without breaking builds
Inventory which pipelines actually reference which groups, move real secrets to Key Vault-backed groups or service connections, mark values secret so they cannot be echoed, and retire unused variables through a staged process — flag, observe, remove — instead of a heroic Friday purge.
Where a control plane helps
Kangl's estate inventory includes the pipeline configuration surface, which makes 'what still references this?' answerable before deletion. Its own integration secrets never enter variable groups at all — they live in managed secret storage, resolved server-side — and retired-variable cleanup can run as a governed, audited operation rather than folklore.

