Azure Key Vault Certificate
This page shows how to write Terraform for Key Vault Certificate and write them securely.
azurerm_key_vault_certificate (Terraform)
The Certificate in Key Vault can be configured in Terraform with the resource name azurerm_key_vault_certificate. The following sections describe 7 examples of how to use the resource and its parameters.
Example Usage from GitHub
resource "azurerm_key_vault_certificate" "non-usage" {
name = "imported-cert"
key_vault_id = azurerm_key_vault.standard.id
certificate {
contents = ""
resource "azurerm_key_vault_certificate" "minio" {
name = "bucket"
key_vault_id = azurerm_key_vault.key.id
certificate {
contents = filebase64("./cert/pem/minio.contratoagil.cl/cert-minio.pfx")
resource "azurerm_key_vault_certificate" "minio" {
name = "bucket"
key_vault_id = azurerm_key_vault.key.id
certificate {
contents = filebase64("./cert/pem/minio.contratoagil.cl/cert-minio.pfx")
resource "azurerm_key_vault_certificate" "minio" {
name = "bucket"
key_vault_id = azurerm_key_vault.key.id
certificate {
contents = filebase64("./cert/pem/minio.onr.cl/cert-minio.pfx")
resource "azurerm_key_vault_certificate" "minio" {
name = "bucket"
key_vault_id = azurerm_key_vault.key.id
certificate {
contents = filebase64("./cert/pem/minio.onr.cl/cert-minio.pfx")
resource "azurerm_key_vault_certificate" "key_vault_certificate" {
name = var.certificate_name
key_vault_id = var.key_vault_id
certificate {
contents = filebase64(var.certificate)
resource "azurerm_key_vault_certificate" "base" {
name = "P2SRootCert"
key_vault_id = var.key_vault_id
certificate {
contents = var.certificate_contents
Parameters
-
certificate_attributeoptional computed - list of object-
created- string -
enabled- bool -
expires- string -
not_before- string -
recovery_level- string -
updated- string
-
-
certificate_dataoptional computed - string -
certificate_data_base64optional computed - string -
idoptional computed - string -
key_vault_idrequired - string -
namerequired - string -
secret_idoptional computed - string -
tagsoptional - map from string to string -
thumbprintoptional computed - string -
versionoptional computed - string -
certificatelist block -
certificate_policylist block-
issuer_parameterslist block-
namerequired - string
-
-
key_propertieslist block-
exportablerequired - bool -
key_sizerequired - number -
key_typerequired - string -
reuse_keyrequired - bool
-
-
lifetime_actionlist block-
actionlist block-
action_typerequired - string
-
-
triggerlist block-
days_before_expiryoptional - number -
lifetime_percentageoptional - number
-
-
-
secret_propertieslist block-
content_typerequired - string
-
-
x509_certificate_propertieslist block-
extended_key_usageoptional computed - list of string -
key_usagerequired - list of string -
subjectrequired - string -
validity_in_monthsrequired - number -
subject_alternative_nameslist block
-
-
-
timeoutssingle block
Explanation in Terraform Registry
Manages a Key Vault Certificate.
Tips: Best Practices for The Other Azure Key Vault Resources
In addition to the azurerm_key_vault, Azure Key Vault has the other resources that should be configured for security reasons. Please check some examples of those resources and precautions.
azurerm_key_vault
Ensure to specify a network ACL for the key vault
It is better to specify network ACL for the key vault. The default should be set to deny and Azure Services should be still accepted.
azurerm_key_vault_key
Ensure to configure the expiration date on all keys
It is better to configure the expiration date on all keys which is not set by default.
azurerm_key_vault_secret
Ensure to set a content type
It is better to set a content type to aid interpretation on retrieval.
Azure Resource Manager Example
Azure Resource Manager code does not have the related resource.
Frequently asked questions
What is Azure Key Vault Certificate?
Azure Key Vault Certificate is a resource for Key Vault of Microsoft Azure. Settings can be wrote in Terraform.
Where can I find the example code for the Azure Key Vault Certificate?
For Terraform, the gilyas/infracost, oliverhernandezmoreno/SourcesOH and oliverhernandezmoreno/SourcesOH source code examples are useful. See the Terraform Example section for further details.