# Key Vault

Source: /azure/services/key-vault/

## Introduction

Azure Key Vault is a managed service for securely storing and accessing secrets, keys, and certificates.
It helps centralize sensitive configuration and credentials for your applications and services.
Key Vault also supports secure key management and certificate lifecycle operations. For more information, see [About Azure Key Vault](https://learn.microsoft.com/en-us/azure/key-vault/general/overview).

LocalStack for Azure provides a local environment for building and testing applications that make use of Azure Key Vault.
The supported APIs are available on our [API Coverage section](#api-coverage), which provides information on the extent of Key Vault's integration with LocalStack.

## Getting started

This guide is designed for users new to Key Vault and assumes basic knowledge of the Azure CLI and our `lstk az` proxy.

Launch LocalStack using your preferred method. For more information, see [Introduction to LocalStack for Azure](/azure/getting-started/). Once the container is running, enable Azure CLI interception by running:

```bash
lstk az start-interception
```

This command points the `az` CLI away from the public Azure management REST API and toward the LocalStack for Azure emulator API.
To revert this configuration, run:

```bash
lstk az stop-interception
```

This reconfigures the `az` CLI to send commands to the official Azure management REST API.

### Create a resource group

Create a resource group that will contain your Key Vault resources:

```bash
az group create \
  --name rg-keyvault-demo \
  --location westeurope
```

```bash title="Output"
{
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-keyvault-demo",
  "location": "westeurope",
  "name": "rg-keyvault-demo",
  "properties": {
    "provisioningState": "Succeeded"
  },
  ...
}
```

### Create a Key Vault

Create a Key Vault in your resource group:

```bash
az keyvault create \
  --name kv-demo-localstack \
  --resource-group rg-keyvault-demo \
  --location westeurope
```

```bash title="Output"
{
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-keyvault-demo/providers/Microsoft.KeyVault/vaults/kv-demo-localstack",
  "location": "westeurope",
  "name": "kv-demo-localstack",
  "properties": {
    ...
    "provisioningState": "Succeeded",
    ...
    "vaultUri": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/"
  },
  ...
}
```

### Add and read a secret

Create a secret in the vault:

```bash
az keyvault secret set \
  --vault-name kv-demo-localstack \
  --name app-secret \
  --value "super-secret-value"
```

```bash title="Output"
{
  "attributes": {
    "enabled": true,
    ...
  },
  "id": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/secrets/app-secret/8e2e69e2e4294f6083715973662d8091",
  "name": "app-secret",
  ...
  "value": "super-secret-value"
}
```

Read the secret value:

```bash
az keyvault secret show \
  --vault-name kv-demo-localstack \
  --name app-secret
```

```bash title="Output"
{
  "attributes": {
    "enabled": true,
    ...
  },
  "id": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/secrets/app-secret/8e2e69e2e4294f6083715973662d8091",
  "name": "app-secret",
  ...
  "value": "super-secret-value"
}
```

List all secrets in the vault:

```bash
az keyvault secret list \
  --vault-name kv-demo-localstack
```

```bash title="Output"
[
  {
    ...
    "id": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/secrets/app-secret",
    "name": "app-secret",
    ...
  }
]
```

### Create and use a key

Create an RSA key in the vault:

```bash
az keyvault key create \
  --vault-name kv-demo-localstack \
  --name app-key \
  --kty RSA \
  --size 2048
```

```bash title="Output"
{
  "attributes": {
    "enabled": true,
    "exportable": false,
    ...
    "keySize": 2048,
    "recoverableDays": 90,
    "recoveryLevel": "Recoverable+Purgeable",
    ...
  },
  "key": {
    "e": "AQAB",
    "keyOps": [
      "encrypt",
      "decrypt",
      "sign",
      "verify",
      "wrapKey",
      "unwrapKey"
    ],
    "kid": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/keys/app-key/8415308e8f3a45e480e490b79d1df0e5",
    "kty": "RSA",
    ...
  },
  ...
}
```

Encrypt the Base64 encoding of `hello world` with the key, and capture the ciphertext for the next step:

```bash
export CIPHERTEXT=$(az keyvault key encrypt \
  --vault-name kv-demo-localstack \
  --name app-key \
  --algorithm RSA-OAEP-256 \
  --value "aGVsbG8gd29ybGQ=" \
  --data-type base64 \
  --query result \
  --output tsv)
```

Decrypt the ciphertext to get the original value back:

```bash
az keyvault key decrypt \
  --vault-name kv-demo-localstack \
  --name app-key \
  --algorithm RSA-OAEP-256 \
  --value "$CIPHERTEXT" \
  --data-type base64
```

```bash title="Output"
{
  "algorithm": "RSA-OAEP-256",
  "kid": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/keys/app-key/8415308e8f3a45e480e490b79d1df0e5",
  "result": "aGVsbG8gd29ybGQ="
}
```

:::note
`az keyvault key encrypt` and `az keyvault key decrypt` are preview commands in the Azure CLI and print a preview warning before their output.
:::

## Features

- **Secrets**: Set, get, list, and update secrets and their versions, including soft delete with recover and purge.
- **Keys**: Create and import RSA and EC keys and use them to encrypt, decrypt, wrap, unwrap, sign, and verify. Rotate keys on demand or through a rotation policy.
- **Keys through the management plane**: Create, get, and list keys and their versions with the `Microsoft.KeyVault/vaults/keys` resource.
- **Certificates**: Create self-signed certificates, get and update their policies, and list their versions. Delete, recover, and purge certificates under soft delete, and manage the vault's certificate contacts.
- **Certificate issuers**: Create, get, update, list, and delete certificate issuers.
- **Backup and restore**: Back up secrets, keys, and certificates and restore them into a vault.

## Limitations

- **Managed HSM is not supported**: The emulator does not provision managed HSM pools. Listing them returns an empty result, so tools that enumerate them keep working.
- **HSM-protected keys are not supported**: The emulator rejects the `RSA-HSM`, `EC-HSM`, and `oct-HSM` key types when you create or import a key, in every vault, because it has no HSM to back them. Azure accepts them in a premium vault. Exportable keys require one of these types, so secure key release is not available either.
- **Certificate issuers are metadata-only**: The emulator stores issuers but does not enroll certificates with a certificate authority. A certificate whose policy names a stored issuer, such as a DigiCert issuer, is rejected with `BadParameter`. Azure instead sends the request to the authority and reports its progress on the pending certificate operation. Use the `Self` issuer in the emulator. The `Unknown` issuer is accepted, but the emulator self-signs the certificate and completes its operation at once, where Azure leaves the operation `inProgress` until you merge a certificate signed by your own authority. Merging is not supported.
- **Certificate lifetime actions are metadata-only**: The emulator stores the `AutoRenew` and `EmailContacts` actions of a certificate policy but never renews the certificate or notifies its contacts.
- **Key rotation policies do not run on a schedule**: The emulator has no scheduler. A rotation that a policy makes due happens the next time any key in the vault is read or listed, not at the scheduled time.
- **Backups are not encrypted**: A backup of a secret, key, or certificate is unencrypted JSON that contains the secret value or the private key, and it restores into a vault in any subscription or geography. Azure encrypts the backup and restores it only into a vault in the same subscription and geography.
- **RBAC enforcement is opt-in**: By default, data-plane operations succeed regardless of role assignments and access policies. Set `LS_AZURE_ENFORCE_RBAC` to enforce roles such as `Key Vault Secrets User`, `Key Vault Certificates Officer`, or `Key Vault Crypto Officer` on vaults created with `enableRbacAuthorization=true`, and access policies on the other vaults. A role assignment or access policy that names a security group does not apply to the group's members. See [Role Assignment: Enabling RBAC enforcement](/azure/services/role-assignment/#enabling-rbac-enforcement).

## Samples

The following samples demonstrate how to use Azure Key Vault with LocalStack for Azure:

- [Azure Container Instances, Key Vault, and Storage (Python)](https://github.com/localstack/localstack-azure-samples/tree/main/samples/aci-blob-storage/python)
- [Azure Web App with Azure SQL Database and Azure Key Vault (Python)](https://github.com/localstack/localstack-azure-samples/tree/main/samples/web-app-sql-database/python)
- [Azure Web App with Azure SQL Database and Azure Key Vault (.NET)](https://github.com/localstack/localstack-azure-samples/tree/main/samples/web-app-sql-database/dotnet)
- [Azure Web App with Azure App Configuration and Azure Key Vault (Python)](https://github.com/localstack/localstack-azure-samples/tree/main/samples/web-app-app-configuration/python)
- [Azure Web App with Azure App Configuration and Azure Key Vault (.NET)](https://github.com/localstack/localstack-azure-samples/tree/main/samples/web-app-app-configuration/dotnet)
- [URL Shortener with Web App, Functions, Storage, Key Vault, Service Bus, and PostgreSQL (Python)](https://github.com/localstack/localstack-azure-samples/tree/main/samples/url-shortener/python)
- [Payment fraud detection pipeline with Event Hubs, Functions, and Capture (Python)](https://github.com/localstack/localstack-azure-samples/tree/main/samples/eventhubs/python)
- [Azure App Configuration and Azure Key Vault on AKS](https://github.com/localstack-samples/aks-samples/tree/main/samples/web-app-app-configuration)
- [Azure Key Vault Provider for Secrets Store CSI Driver on AKS](https://github.com/localstack-samples/aks-samples/tree/main/tutorials/key-vault-csi-driver)

## API Coverage


### Key Vault API coverage

Source service: `key-vault`. 85 of 147 tracked operations are implemented.

Service documentation: /azure/services/key-vault/

| Operation | Status |
| --- | --- |
| HsmSecurityDomain.Download | Not implemented |
| HsmSecurityDomain.DownloadPending | Not implemented |
| HsmSecurityDomain.TransferKey | Not implemented |
| HsmSecurityDomain.Upload | Not implemented |
| HsmSecurityDomain.UploadPending | Not implemented |
| Keys.CreateIfNotExist | Implemented |
| Keys.Get | Implemented |
| Keys.GetVersion | Implemented |
| Keys.List | Implemented |
| Keys.ListVersions | Implemented |
| MHsmPrivateEndpointConnections.Delete | Not implemented |
| MHsmPrivateEndpointConnections.Get | Not implemented |
| MHsmPrivateEndpointConnections.ListByResource | Not implemented |
| MHsmPrivateEndpointConnections.Put | Not implemented |
| MHsmPrivateLinkResources.ListByMhsmResource | Not implemented |
| MHsmRegions.ListByResource | Not implemented |
| ManagedHsmKeys.CreateIfNotExist | Not implemented |
| ManagedHsmKeys.Get | Not implemented |
| ManagedHsmKeys.GetVersion | Not implemented |
| ManagedHsmKeys.List | Not implemented |
| ManagedHsmKeys.ListVersions | Not implemented |
| ManagedHsms.CheckMhsmNameAvailability | Not implemented |
| ManagedHsms.CreateOrUpdate | Not implemented |
| ManagedHsms.Delete | Not implemented |
| ManagedHsms.Get | Not implemented |
| ManagedHsms.GetDeleted | Not implemented |
| ManagedHsms.ListByResourceGroup | Implemented |
| ManagedHsms.ListBySubscription | Implemented |
| ManagedHsms.ListDeleted | Implemented |
| ManagedHsms.PurgeDeleted | Not implemented |
| ManagedHsms.Update | Not implemented |
| Microsoft.KeyVault.BackupCertificate | Implemented |
| Microsoft.KeyVault.BackupKey | Implemented |
| Microsoft.KeyVault.BackupSecret | Implemented |
| Microsoft.KeyVault.BackupStorageAccount | Not implemented |
| Microsoft.KeyVault.CreateCertificate | Implemented |
| Microsoft.KeyVault.CreateKey | Implemented |
| Microsoft.KeyVault.Decrypt | Implemented |
| Microsoft.KeyVault.DeleteCertificate | Implemented |
| Microsoft.KeyVault.DeleteCertificateContacts | Implemented |
| Microsoft.KeyVault.DeleteCertificateIssuer | Implemented |
| Microsoft.KeyVault.DeleteCertificateOperation | Not implemented |
| Microsoft.KeyVault.DeleteKey | Implemented |
| Microsoft.KeyVault.DeleteSasDefinition | Not implemented |
| Microsoft.KeyVault.DeleteSecret | Implemented |
| Microsoft.KeyVault.DeleteStorageAccount | Not implemented |
| Microsoft.KeyVault.Encrypt | Implemented |
| Microsoft.KeyVault.FullBackup | Not implemented |
| Microsoft.KeyVault.FullBackupStatus | Not implemented |
| Microsoft.KeyVault.FullRestoreOperation | Not implemented |
| Microsoft.KeyVault.GetCertificate | Implemented |
| Microsoft.KeyVault.GetCertificateContacts | Implemented |
| Microsoft.KeyVault.GetCertificateIssuer | Implemented |
| Microsoft.KeyVault.GetCertificateIssuers | Implemented |
| Microsoft.KeyVault.GetCertificateOperation | Implemented |
| Microsoft.KeyVault.GetCertificatePolicy | Implemented |
| Microsoft.KeyVault.GetCertificateVersions | Implemented |
| Microsoft.KeyVault.GetCertificates | Implemented |
| Microsoft.KeyVault.GetDeletedCertificate | Implemented |
| Microsoft.KeyVault.GetDeletedCertificates | Implemented |
| Microsoft.KeyVault.GetDeletedKey | Implemented |
| Microsoft.KeyVault.GetDeletedKeys | Implemented |
| Microsoft.KeyVault.GetDeletedSasDefinition | Not implemented |
| Microsoft.KeyVault.GetDeletedSasDefinitions | Not implemented |
| Microsoft.KeyVault.GetDeletedSecret | Implemented |
| Microsoft.KeyVault.GetDeletedSecrets | Implemented |
| Microsoft.KeyVault.GetDeletedStorageAccount | Not implemented |
| Microsoft.KeyVault.GetDeletedStorageAccounts | Not implemented |
| Microsoft.KeyVault.GetKey | Implemented |
| Microsoft.KeyVault.GetKeyAttestation | Not implemented |
| Microsoft.KeyVault.GetKeyRotationPolicy | Implemented |
| Microsoft.KeyVault.GetKeyVersions | Implemented |
| Microsoft.KeyVault.GetKeys | Implemented |
| Microsoft.KeyVault.GetRandomBytes | Not implemented |
| Microsoft.KeyVault.GetSasDefinition | Not implemented |
| Microsoft.KeyVault.GetSasDefinitions | Not implemented |
| Microsoft.KeyVault.GetSecret | Implemented |
| Microsoft.KeyVault.GetSecretVersions | Implemented |
| Microsoft.KeyVault.GetSecrets | Implemented |
| Microsoft.KeyVault.GetSetting | Not implemented |
| Microsoft.KeyVault.GetSettings | Not implemented |
| Microsoft.KeyVault.GetStorageAccount | Not implemented |
| Microsoft.KeyVault.GetStorageAccounts | Not implemented |
| Microsoft.KeyVault.ImportCertificate | Not implemented |
| Microsoft.KeyVault.ImportKey | Implemented |
| Microsoft.KeyVault.MergeCertificate | Not implemented |
| Microsoft.KeyVault.PreFullBackup | Not implemented |
| Microsoft.KeyVault.PreFullRestoreOperation | Not implemented |
| Microsoft.KeyVault.PurgeDeletedCertificate | Implemented |
| Microsoft.KeyVault.PurgeDeletedKey | Implemented |
| Microsoft.KeyVault.PurgeDeletedSecret | Implemented |
| Microsoft.KeyVault.PurgeDeletedStorageAccount | Not implemented |
| Microsoft.KeyVault.RecoverDeletedCertificate | Implemented |
| Microsoft.KeyVault.RecoverDeletedKey | Implemented |
| Microsoft.KeyVault.RecoverDeletedSasDefinition | Not implemented |
| Microsoft.KeyVault.RecoverDeletedSecret | Implemented |
| Microsoft.KeyVault.RecoverDeletedStorageAccount | Not implemented |
| Microsoft.KeyVault.RegenerateStorageAccountKey | Not implemented |
| Microsoft.KeyVault.Release | Not implemented |
| Microsoft.KeyVault.RestoreCertificate | Implemented |
| Microsoft.KeyVault.RestoreKey | Implemented |
| Microsoft.KeyVault.RestoreSecret | Implemented |
| Microsoft.KeyVault.RestoreStatus | Not implemented |
| Microsoft.KeyVault.RestoreStorageAccount | Not implemented |
| Microsoft.KeyVault.RotateKey | Implemented |
| Microsoft.KeyVault.SelectiveKeyRestoreOperation | Not implemented |
| Microsoft.KeyVault.SelectiveKeyRestoreStatus | Not implemented |
| Microsoft.KeyVault.SetCertificateContacts | Implemented |
| Microsoft.KeyVault.SetCertificateIssuer | Implemented |
| Microsoft.KeyVault.SetSasDefinition | Not implemented |
| Microsoft.KeyVault.SetSecret | Implemented |
| Microsoft.KeyVault.SetStorageAccount | Not implemented |
| Microsoft.KeyVault.Sign | Implemented |
| Microsoft.KeyVault.UnwrapKey | Implemented |
| Microsoft.KeyVault.UpdateCertificate | Implemented |
| Microsoft.KeyVault.UpdateCertificateIssuer | Implemented |
| Microsoft.KeyVault.UpdateCertificateOperation | Not implemented |
| Microsoft.KeyVault.UpdateCertificatePolicy | Implemented |
| Microsoft.KeyVault.UpdateKey | Implemented |
| Microsoft.KeyVault.UpdateKeyRotationPolicy | Implemented |
| Microsoft.KeyVault.UpdateSasDefinition | Not implemented |
| Microsoft.KeyVault.UpdateSecret | Implemented |
| Microsoft.KeyVault.UpdateSetting | Not implemented |
| Microsoft.KeyVault.UpdateStorageAccount | Not implemented |
| Microsoft.KeyVault.Verify | Implemented |
| Microsoft.KeyVault.WrapKey | Implemented |
| Operations.List | Not implemented |
| PrivateEndpointConnections.Delete | Implemented |
| PrivateEndpointConnections.Get | Implemented |
| PrivateEndpointConnections.ListByResource | Implemented |
| PrivateEndpointConnections.Put | Implemented |
| PrivateLinkResources.ListByVault | Implemented |
| Secrets.CreateOrUpdate | Implemented |
| Secrets.Get | Implemented |
| Secrets.List | Implemented |
| Secrets.Update | Implemented |
| Vaults.CheckNameAvailability | Implemented |
| Vaults.CreateOrUpdate | Implemented |
| Vaults.Delete | Implemented |
| Vaults.Get | Implemented |
| Vaults.GetDeleted | Implemented |
| Vaults.ListByResourceGroup | Implemented |
| Vaults.ListBySubscription | Implemented |
| Vaults.ListDeleted | Implemented |
| Vaults.PurgeDeleted | Implemented |
| Vaults.Update | Implemented |
| Vaults.UpdateAccessPolicy | Implemented |
