Skip to main content
Version: v0.25.0 (Latest)

Configure the Azure Key Vault provider

Step 2 of 5 in Connect Azure KMS with BYOK and BYOC.

Collect the HTTPS vault or Managed HSM URI, the Microsoft Entra tenant id, the workload client id and the Azure role assignments before starting. Wrong role assignments surface as a validation failure, not as a configuration error.

For a tenant-owned vault, create the resource with kind: AZURE_KEY_VAULT and the vault coordinates. The response returns a handle, a resourceVersion and a credentialSecretRef.

Loading example...

Attach the Azure client secret against that handle and version. The secret is write-only and is stored in the tenant secret store; the value never travels back.

Loading example...

Validation proves the provider can reach the vault with the configured identity. Treat anything other than a successful validation as a stop.

Loading example...

For a platform-owned shared vault, the platform operator offers the provider and the tenant enables it instead of creating a second resource. The operator either creates that provider through these calls on the platform tenant or declares it in the deployment configuration, as described in Cloud KMS providers. Sharing the provider does not share every key: each Azure object a tenant may use must carry the tag sphereon-tenant-id=<tenant id>.

Loading example...

Next​

Continue with step 3, Register an existing Azure key (BYOK).