azure-service-operator icon indicating copy to clipboard operation
azure-service-operator copied to clipboard

Feature: Additional KeyVault resources

Open theunrepentantgeek opened this issue 2 years ago • 7 comments

Requesting the following additional resources from Microsoft.KeyVault:

theunrepentantgeek avatar May 03 '23 20:05 theunrepentantgeek

Looks like AccessPolicy is not supported as a resource in the API specs. Although, I did try to update and delete the KeyVault resource AccessPoliciesEntries with a new AccessPolicy which works fine.

Also, PrivateEndpointConnection is not a resource, to create a PrivateEndpoint to KeyVault, user must create a PrivateEndpoint resource which we support and specify the KeyVault in privateLinkReference as how we do for StorageAccount here. The PrivateEndpointConnection resource you mentioned looks more like a PrivateEndpointConnection approval/denial template.

super-harsh avatar May 10 '23 03:05 super-harsh

Moving to v2.2.0 - possibly we just close this if there's nothing to do @super-harsh

theunrepentantgeek avatar May 31 '23 04:05 theunrepentantgeek

It might also make sense to support the sorts of secrets AKV generates

matthchr avatar Jun 03 '23 05:06 matthchr

A specific customer request is for AccessPolicy as a separate resource so it can be managed with a different lifecycle - and by a different team.

theunrepentantgeek avatar Jun 14 '23 20:06 theunrepentantgeek

It looks like AccessPolicies is there, but it's a bit weirdly shaped

matthchr avatar Jun 14 '23 20:06 matthchr

We should doublecheck the KV RBAC vs KV AccessPolicies discussion too - which is now recommended or do they both serve different purposes?

edit: It looks like we need to do some research into KV AccessPolicies vs RBAC and understand what the difference is -- possibly we can talk to somebody on the KV team after reading their docs more carefully.

matthchr avatar Jan 22 '24 23:01 matthchr

No change from above.

matthchr avatar May 13 '24 23:05 matthchr

No change from above still - not seeing a lot of user complaints about this missing capability at the moment.

matthchr avatar Aug 25 '25 22:08 matthchr