Managed Hardware Security Module Key Rotation Policy
Manages a Managed HSM Key rotation policy.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as azure from "@pulumi/azure";
const example = new azure.keyvault.ManagedHardwareSecurityModuleKey("example", {
name: "example-key",
managedHsmId: exampleAzurermKeyVaultManagedHardwareSecurityModule.id,
keyType: "EC-HSM",
curve: "P-521",
keyOpts: ["sign"],
});
const exampleManagedHardwareSecurityModuleKeyRotationPolicy = new azure.keyvault.ManagedHardwareSecurityModuleKeyRotationPolicy("example", {
managedHsmKeyId: example.id,
expireAfter: "P60D",
timeBeforeExpiry: "P30D",
});
Content copied to clipboard
import pulumi
import pulumi_azure as azure
example = azure.keyvault.ManagedHardwareSecurityModuleKey("example",
name="example-key",
managed_hsm_id=example_azurerm_key_vault_managed_hardware_security_module["id"],
key_type="EC-HSM",
curve="P-521",
key_opts=["sign"])
example_managed_hardware_security_module_key_rotation_policy = azure.keyvault.ManagedHardwareSecurityModuleKeyRotationPolicy("example",
managed_hsm_key_id=example.id,
expire_after="P60D",
time_before_expiry="P30D")
Content copied to clipboard
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Azure = Pulumi.Azure;
return await Deployment.RunAsync(() =>
{
var example = new Azure.KeyVault.ManagedHardwareSecurityModuleKey("example", new()
{
Name = "example-key",
ManagedHsmId = exampleAzurermKeyVaultManagedHardwareSecurityModule.Id,
KeyType = "EC-HSM",
Curve = "P-521",
KeyOpts = new[]
{
"sign",
},
});
var exampleManagedHardwareSecurityModuleKeyRotationPolicy = new Azure.KeyVault.ManagedHardwareSecurityModuleKeyRotationPolicy("example", new()
{
ManagedHsmKeyId = example.Id,
ExpireAfter = "P60D",
TimeBeforeExpiry = "P30D",
});
});
Content copied to clipboard
package main
import (
"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/keyvault"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
example, err := keyvault.NewManagedHardwareSecurityModuleKey(ctx, "example", &keyvault.ManagedHardwareSecurityModuleKeyArgs{
Name: pulumi.String("example-key"),
ManagedHsmId: pulumi.Any(exampleAzurermKeyVaultManagedHardwareSecurityModule.Id),
KeyType: pulumi.String("EC-HSM"),
Curve: pulumi.String("P-521"),
KeyOpts: pulumi.StringArray{
pulumi.String("sign"),
},
})
if err != nil {
return err
}
_, err = keyvault.NewManagedHardwareSecurityModuleKeyRotationPolicy(ctx, "example", &keyvault.ManagedHardwareSecurityModuleKeyRotationPolicyArgs{
ManagedHsmKeyId: example.ID(),
ExpireAfter: pulumi.String("P60D"),
TimeBeforeExpiry: pulumi.String("P30D"),
})
if err != nil {
return err
}
return nil
})
}
Content copied to clipboard
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.azure.keyvault.ManagedHardwareSecurityModuleKey;
import com.pulumi.azure.keyvault.ManagedHardwareSecurityModuleKeyArgs;
import com.pulumi.azure.keyvault.ManagedHardwareSecurityModuleKeyRotationPolicy;
import com.pulumi.azure.keyvault.ManagedHardwareSecurityModuleKeyRotationPolicyArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var example = new ManagedHardwareSecurityModuleKey("example", ManagedHardwareSecurityModuleKeyArgs.builder()
.name("example-key")
.managedHsmId(exampleAzurermKeyVaultManagedHardwareSecurityModule.id())
.keyType("EC-HSM")
.curve("P-521")
.keyOpts("sign")
.build());
var exampleManagedHardwareSecurityModuleKeyRotationPolicy = new ManagedHardwareSecurityModuleKeyRotationPolicy("exampleManagedHardwareSecurityModuleKeyRotationPolicy", ManagedHardwareSecurityModuleKeyRotationPolicyArgs.builder()
.managedHsmKeyId(example.id())
.expireAfter("P60D")
.timeBeforeExpiry("P30D")
.build());
}
}
Content copied to clipboard
resources:
example:
type: azure:keyvault:ManagedHardwareSecurityModuleKey
properties:
name: example-key
managedHsmId: ${exampleAzurermKeyVaultManagedHardwareSecurityModule.id}
keyType: EC-HSM
curve: P-521
keyOpts:
- sign
exampleManagedHardwareSecurityModuleKeyRotationPolicy:
type: azure:keyvault:ManagedHardwareSecurityModuleKeyRotationPolicy
name: example
properties:
managedHsmKeyId: ${example.id}
expireAfter: P60D
timeBeforeExpiry: P30D
Content copied to clipboard
Import
Managed HSM Key rotation policy can be imported using the resource id
, e.g.
$ pulumi import azure:keyvault/managedHardwareSecurityModuleKeyRotationPolicy:ManagedHardwareSecurityModuleKeyRotationPolicy example https://example-hsm.managedhsm.azure.net/keys/example
Content copied to clipboard
Properties
Link copied to clipboard
Specify the expiration duration on a newly rotated key as an ISO 8601 duration. The minimum duration is P28D
.
Link copied to clipboard
The ID of the Managed HSM Key. Changing this forces a new Managed HSM Key rotation policy to be created.
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Rotate automatically at a duration after key creation as an ISO 8601 duration. Exactly one of time_after_creation
or time_before_expiry
should be specified.
Link copied to clipboard
Rotate automatically at a duration before key expiry as an ISO 8601 duration. Exactly one of time_after_creation
or time_before_expiry
should be specified.