Key Vault
Azure Key Vault stores secrets, keys and certificates behind Microsoft Entra authorization. The Azure platform uses five kinds of vault, each with one job, and applies the same controls to all of them: RBAC authorization only, soft delete with purge protection, audit logging and a delete lock.
What it does
A vault holds secrets (any value, versioned), keys (RSA or elliptic-curve, used for encryption and signing without ever leaving the vault) and certificates. Access is either by legacy access policies or by Azure RBAC, where data-plane roles such as Key Vault Secrets User (read secrets), Secrets Officer (manage secrets), Crypto User (use keys) and Crypto Service Encryption User (wrap and unwrap for a service) are granted at the vault, or at a single key or secret. Soft delete keeps a deleted vault or object recoverable for 7 to 90 days, and purge protection forbids purging it before that period ends. The standard SKU protects keys in software; premium adds HSM-backed (hardware security module) keys.
How BuiltForProd uses it
| Vault | Product | Subscription | Holds |
|---|---|---|---|
kv-acme-eus2-auto-plat | Azure Enterprise Baseline | acme-core-auto | The GitHub App credentials of the runners and of ArgoCD's GitOps pull requests, entered by hand |
kv-acme-eus2-<stage>-plat | Azure Enterprise Baseline | each plat subscription | The landing-zone contract: 29 secrets named <area>--<name> (24 base, 5 platform services) |
kv-acme-eus2-sec-sops | Azure Enterprise Baseline | acme-core-security | The SOPS keys sops-sandbox, -dev, -staging, -prod: RSA 4096, rotated yearly |
kv-acme-eus2-audit-cmk | Azure Enterprise Baseline | acme-core-audit | audit-storage, the customer-managed key of the audit storage: RSA 3072, rotated yearly |
kv-acme-eus2-<stage>-app | Web App Blueprint | each stage subscription | Data-store host names and ports, the Application Insights connection string, and the <app>--<KEY> secrets of the Secrets Blueprint |
<stage> is the short stage code (sbx, dev, stg, prd), so prod's contract vault is kv-acme-eus2-prd-plat. Vault names stop at 24 characters, which is why the SOPS vault is sec-sops.
Controls on every vault.
- RBAC authorization only (
rbac_authorization_enabled = true); no access policies. Grants are as narrow as the vault allows: the SOPS keys carry key-scoped Crypto User grants, so a developer can use the dev key but not the prod key. - Soft delete for 90 days and purge protection. The security guardrails initiative of Azure Policy denies any vault without either, and audits vaults with public network access.
CanNotDeletelock on the vault's resource group (on the vault itself for the contract vault and, in prod, the application vault) andprevent_destroyin code.- Audit logging: an
AuditEventdiagnostic setting to the audit workspace. - Network: the contract vault has a private endpoint in the spoke's
snet-endpointsand the application vault is private from creation, reachable only through its private endpoint from the cluster and the self-hosted runners. The Baseline's vaults keep public network access on by default, with Entra RBAC on every request, behind thepublic_network_access_enabledswitch; the SOPS vault keeps it on by design, so developers can runsopsfrom their workstations. - Keys rotate automatically: a rotation policy creates a new version after
rotation_days(365) and expires versions after twice that.
Who reads what. The four blueprint pipelines hold Key Vault Secrets Officer on the contract vault: they read the landing zone's values through their deployer identities and record a few of their own, such as deployed image tags. Platform Leads manage it, and Platform Engineers and DevOps Leads may read it. In the cluster, the External Secrets Operator and the application read the application vault through their managed identities (Key Vault Secrets User); the secrets syncer of the Secrets Blueprint writes to it. The Baseline's vault module waits two minutes after granting data-plane roles before its first write, because Key Vault RBAC takes that long to propagate.
The vaults use the standard SKU; sku_name = "premium" gives HSM-backed keys at about $1 per key version per month, as the unit comments state.
Terms you will see
| Term | Meaning |
|---|---|
| Contract vault | The per-stage vault kv-acme-eus2-<stage>-plat the blueprints read the landing zone from. |
| Soft delete | A deleted vault or object stays recoverable for the retention period, 90 days here. |
| Purge protection | Nobody can permanently delete before soft delete expires. |
| Key-scoped role | A role assignment on one key rather than the whole vault. |
| Customer-managed key | A key you control that encrypts a service's data, here the audit storage. |
| Rotation policy | The key setting that creates new versions on a schedule. |
Where to read more
- Azure Enterprise Baseline overview and Azure Web App Blueprint overview.
- SOPS for how the per-stage keys encrypt application secrets.
- Least privilege for why each vault and key has its own readers.