Skip to content
Get Started for Free

Key Vault

Azure Key Vault is a managed service for securely storing and accessing secrets, keys, and certificates. It helps centralize sensitive configuration and credentials for your applications and services. Key Vault also supports secure key management and certificate lifecycle operations. For more information, see About Azure Key Vault.

LocalStack for Azure provides a local environment for building and testing applications that make use of Azure Key Vault. The supported APIs are available on our API Coverage section, which provides information on the extent of Key Vault’s integration with LocalStack.

This guide is designed for users new to Key Vault and assumes basic knowledge of the Azure CLI and our lstk az proxy.

Launch LocalStack using your preferred method. For more information, see Introduction to LocalStack for Azure. Once the container is running, enable Azure CLI interception by running:

Terminal window
lstk az start-interception

This command points the az CLI away from the public Azure management REST API and toward the LocalStack for Azure emulator API. To revert this configuration, run:

Terminal window
lstk az stop-interception

This reconfigures the az CLI to send commands to the official Azure management REST API.

Create a resource group that will contain your Key Vault resources:

Terminal window
az group create \
--name rg-keyvault-demo \
--location westeurope
Output
{
"id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-keyvault-demo",
"location": "westeurope",
"name": "rg-keyvault-demo",
"properties": {
"provisioningState": "Succeeded"
},
...
}

Create a Key Vault in your resource group:

Terminal window
az keyvault create \
--name kv-demo-localstack \
--resource-group rg-keyvault-demo \
--location westeurope
Output
{
"id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-keyvault-demo/providers/Microsoft.KeyVault/vaults/kv-demo-localstack",
"location": "westeurope",
"name": "kv-demo-localstack",
"properties": {
...
"provisioningState": "Succeeded",
...
"vaultUri": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/"
},
...
}

Create a secret in the vault:

Terminal window
az keyvault secret set \
--vault-name kv-demo-localstack \
--name app-secret \
--value "super-secret-value"
Output
{
"attributes": {
"enabled": true,
...
},
"id": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/secrets/app-secret/8e2e69e2e4294f6083715973662d8091",
"name": "app-secret",
...
"value": "super-secret-value"
}

Read the secret value:

Terminal window
az keyvault secret show \
--vault-name kv-demo-localstack \
--name app-secret
Output
{
"attributes": {
"enabled": true,
...
},
"id": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/secrets/app-secret/8e2e69e2e4294f6083715973662d8091",
"name": "app-secret",
...
"value": "super-secret-value"
}

List all secrets in the vault:

Terminal window
az keyvault secret list \
--vault-name kv-demo-localstack
Output
[
{
...
"id": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/secrets/app-secret",
"name": "app-secret",
...
}
]

Create an RSA key in the vault:

Terminal window
az keyvault key create \
--vault-name kv-demo-localstack \
--name app-key \
--kty RSA \
--size 2048
Output
{
"attributes": {
"enabled": true,
"exportable": false,
...
"keySize": 2048,
"recoverableDays": 90,
"recoveryLevel": "Recoverable+Purgeable",
...
},
"key": {
"e": "AQAB",
"keyOps": [
"encrypt",
"decrypt",
"sign",
"verify",
"wrapKey",
"unwrapKey"
],
"kid": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/keys/app-key/8415308e8f3a45e480e490b79d1df0e5",
"kty": "RSA",
...
},
...
}

Encrypt the Base64 encoding of hello world with the key, and capture the ciphertext for the next step:

Terminal window
export CIPHERTEXT=$(az keyvault key encrypt \
--vault-name kv-demo-localstack \
--name app-key \
--algorithm RSA-OAEP-256 \
--value "aGVsbG8gd29ybGQ=" \
--data-type base64 \
--query result \
--output tsv)

Decrypt the ciphertext to get the original value back:

Terminal window
az keyvault key decrypt \
--vault-name kv-demo-localstack \
--name app-key \
--algorithm RSA-OAEP-256 \
--value "$CIPHERTEXT" \
--data-type base64
Output
{
"algorithm": "RSA-OAEP-256",
"kid": "https://kv-demo-localstack.vault.azure.localhost.localstack.cloud:4566/keys/app-key/8415308e8f3a45e480e490b79d1df0e5",
"result": "aGVsbG8gd29ybGQ="
}
  • Secrets: Set, get, list, and update secrets and their versions, including soft delete with recover and purge.
  • Keys: Create and import RSA and EC keys and use them to encrypt, decrypt, wrap, unwrap, sign, and verify. Rotate keys on demand or through a rotation policy.
  • Keys through the management plane: Create, get, and list keys and their versions with the Microsoft.KeyVault/vaults/keys resource.
  • Certificates: Create self-signed certificates, get and update their policies, and list their versions. Delete, recover, and purge certificates under soft delete, and manage the vault’s certificate contacts.
  • Certificate issuers: Create, get, update, list, and delete certificate issuers.
  • Backup and restore: Back up secrets, keys, and certificates and restore them into a vault.
  • Managed HSM is not supported: The emulator does not provision managed HSM pools. Listing them returns an empty result, so tools that enumerate them keep working.
  • HSM-protected keys are not supported: The emulator rejects the RSA-HSM, EC-HSM, and oct-HSM key types when you create or import a key, in every vault, because it has no HSM to back them. Azure accepts them in a premium vault. Exportable keys require one of these types, so secure key release is not available either.
  • Certificate issuers are metadata-only: The emulator stores issuers but does not enroll certificates with a certificate authority. A certificate whose policy names a stored issuer, such as a DigiCert issuer, is rejected with BadParameter. Azure instead sends the request to the authority and reports its progress on the pending certificate operation. Use the Self issuer in the emulator. The Unknown issuer is accepted, but the emulator self-signs the certificate and completes its operation at once, where Azure leaves the operation inProgress until you merge a certificate signed by your own authority. Merging is not supported.
  • Certificate lifetime actions are metadata-only: The emulator stores the AutoRenew and EmailContacts actions of a certificate policy but never renews the certificate or notifies its contacts.
  • Key rotation policies do not run on a schedule: The emulator has no scheduler. A rotation that a policy makes due happens the next time any key in the vault is read or listed, not at the scheduled time.
  • Backups are not encrypted: A backup of a secret, key, or certificate is unencrypted JSON that contains the secret value or the private key, and it restores into a vault in any subscription or geography. Azure encrypts the backup and restores it only into a vault in the same subscription and geography.
  • RBAC enforcement is opt-in: By default, data-plane operations succeed regardless of role assignments and access policies. Set LS_AZURE_ENFORCE_RBAC to enforce roles such as Key Vault Secrets User, Key Vault Certificates Officer, or Key Vault Crypto Officer on vaults created with enableRbacAuthorization=true, and access policies on the other vaults. A role assignment or access policy that names a security group does not apply to the group’s members. See Role Assignment: Enabling RBAC enforcement.

The following samples demonstrate how to use Azure Key Vault with LocalStack for Azure:

85 of 147 operations implemented

Operation ▲Implemented ▼
Page 1 of 0
Was this page helpful?