Key Vault
Introduction
Section titled “Introduction”Azure Key Vault is a managed service for securely storing and accessing secrets, keys, and certificates. It helps centralize sensitive configuration and credentials for your applications and services. Key Vault also supports secure key management and certificate lifecycle operations. For more information, see About Azure Key Vault.
LocalStack for Azure provides a local environment for building and testing applications that make use of Azure Key Vault. The supported APIs are available on our API Coverage section, which provides information on the extent of Key Vault’s integration with LocalStack.
Getting started
Section titled “Getting started”This guide is designed for users new to Key Vault and assumes basic knowledge of the Azure CLI and our lstk az proxy.
Launch LocalStack using your preferred method. For more information, see Introduction to LocalStack for Azure. Once the container is running, enable Azure CLI interception by running:
lstk az start-interceptionThis command points the az CLI away from the public Azure management REST API and toward the LocalStack for Azure emulator API.
To revert this configuration, run:
lstk az stop-interceptionThis reconfigures the az CLI to send commands to the official Azure management REST API.
Create a resource group
Section titled “Create a resource group”Create a resource group that will contain your Key Vault resources:
az group create \ --name rg-keyvault-demo \ --location westeurope{ "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-keyvault-demo", "location": "westeurope", "name": "rg-keyvault-demo", "properties": { "provisioningState": "Succeeded" }, ...}Create a Key Vault
Section titled “Create a Key Vault”Create a Key Vault in your resource group:
az keyvault create \ --name kv-demo-localstack \ --resource-group rg-keyvault-demo \ --location westeurope{ "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-keyvault-demo/providers/Microsoft.KeyVault/vaults/kv-demo-localstack", "location": "westeurope", "name": "kv-demo-localstack", "properties": { ... "provisioningState": "Succeeded", ... "vaultUri": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/" }, ...}Add and read a secret
Section titled “Add and read a secret”Create a secret in the vault:
az keyvault secret set \ --vault-name kv-demo-localstack \ --name app-secret \ --value "super-secret-value"{ "attributes": { "enabled": true, ... }, "id": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/secrets/app-secret/8e2e69e2e4294f6083715973662d8091", "name": "app-secret", ... "value": "super-secret-value"}Read the secret value:
az keyvault secret show \ --vault-name kv-demo-localstack \ --name app-secret{ "attributes": { "enabled": true, ... }, "id": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/secrets/app-secret/8e2e69e2e4294f6083715973662d8091", "name": "app-secret", ... "value": "super-secret-value"}List all secrets in the vault:
az keyvault secret list \ --vault-name kv-demo-localstack[ { ... "id": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/secrets/app-secret", "name": "app-secret", ... }]Create and use a key
Section titled “Create and use a key”Create an RSA key in the vault:
az keyvault key create \ --vault-name kv-demo-localstack \ --name app-key \ --kty RSA \ --size 2048{ "attributes": { "enabled": true, "exportable": false, ... "keySize": 2048, "recoverableDays": 90, "recoveryLevel": "Recoverable+Purgeable", ... }, "key": { "e": "AQAB", "keyOps": [ "encrypt", "decrypt", "sign", "verify", "wrapKey", "unwrapKey" ], "kid": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/keys/app-key/8415308e8f3a45e480e490b79d1df0e5", "kty": "RSA", ... }, ...}Encrypt the Base64 encoding of hello world with the key, and capture the ciphertext for the next step:
export CIPHERTEXT=$(az keyvault key encrypt \ --vault-name kv-demo-localstack \ --name app-key \ --algorithm RSA-OAEP-256 \ --value "aGVsbG8gd29ybGQ=" \ --data-type base64 \ --query result \ --output tsv)Decrypt the ciphertext to get the original value back:
az keyvault key decrypt \ --vault-name kv-demo-localstack \ --name app-key \ --algorithm RSA-OAEP-256 \ --value "$CIPHERTEXT" \ --data-type base64{ "algorithm": "RSA-OAEP-256", "kid": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/keys/app-key/8415308e8f3a45e480e490b79d1df0e5", "result": "aGVsbG8gd29ybGQ="}Features
Section titled “Features”- Secrets: Set, get, list, and update secrets and their versions, including soft delete with recover and purge.
- Keys: Create and import RSA and EC keys and use them to encrypt, decrypt, wrap, unwrap, sign, and verify. Rotate keys on demand or through a rotation policy.
- Keys through the management plane: Create, get, and list keys and their versions with the
Microsoft.KeyVault/vaults/keysresource. - Certificates: Create self-signed certificates, get and update their policies, and list their versions. Delete, recover, and purge certificates under soft delete, and manage the vault’s certificate contacts.
- Certificate issuers: Create, get, update, list, and delete certificate issuers.
- Backup and restore: Back up secrets, keys, and certificates and restore them into a vault.
Limitations
Section titled “Limitations”- Managed HSM is not supported: The emulator does not provision managed HSM pools. Listing them returns an empty result, so tools that enumerate them keep working.
- HSM-protected keys are not supported: The emulator rejects the
RSA-HSM,EC-HSM, andoct-HSMkey types when you create or import a key, in every vault, because it has no HSM to back them. Azure accepts them in a premium vault. Exportable keys require one of these types, so secure key release is not available either. - Certificate issuers are metadata-only: The emulator stores issuers but does not enroll certificates with a certificate authority. A certificate whose policy names a stored issuer, such as a DigiCert issuer, is rejected with
BadParameter. Azure instead sends the request to the authority and reports its progress on the pending certificate operation. Use theSelfissuer in the emulator. TheUnknownissuer is accepted, but the emulator self-signs the certificate and completes its operation at once, where Azure leaves the operationinProgressuntil you merge a certificate signed by your own authority. Merging is not supported. - Certificate lifetime actions are metadata-only: The emulator stores the
AutoRenewandEmailContactsactions of a certificate policy but never renews the certificate or notifies its contacts. - Key rotation policies do not run on a schedule: The emulator has no scheduler. A rotation that a policy makes due happens the next time any key in the vault is read or listed, not at the scheduled time.
- Backups are not encrypted: A backup of a secret, key, or certificate is unencrypted JSON that contains the secret value or the private key, and it restores into a vault in any subscription or geography. Azure encrypts the backup and restores it only into a vault in the same subscription and geography.
- RBAC enforcement is opt-in: By default, data-plane operations succeed regardless of role assignments and access policies. Set
LS_AZURE_ENFORCE_RBACto enforce roles such asKey Vault Secrets User,Key Vault Certificates Officer, orKey Vault Crypto Officeron vaults created withenableRbacAuthorization=true, and access policies on the other vaults. A role assignment or access policy that names a security group does not apply to the group’s members. See Role Assignment: Enabling RBAC enforcement.
Samples
Section titled “Samples”The following samples demonstrate how to use Azure Key Vault with LocalStack for Azure:
- Azure Container Instances, Key Vault, and Storage (Python)
- Azure Web App with Azure SQL Database and Azure Key Vault (Python)
- Azure Web App with Azure SQL Database and Azure Key Vault (.NET)
- Azure Web App with Azure App Configuration and Azure Key Vault (Python)
- Azure Web App with Azure App Configuration and Azure Key Vault (.NET)
- URL Shortener with Web App, Functions, Storage, Key Vault, Service Bus, and PostgreSQL (Python)
- Payment fraud detection pipeline with Event Hubs, Functions, and Capture (Python)
- Azure App Configuration and Azure Key Vault on AKS
- Azure Key Vault Provider for Secrets Store CSI Driver on AKS
API Coverage
Section titled “API Coverage”85 of 147 operations implemented
| Operation ▲ | Implemented ▼ |
|---|