Azure Key Vault for secret encryption
So far, we’ve used Azure Key Vault to store sensitive Secrets. What we want to identify is whether we can use Azure Key Vault to encrypt the Secrets that reside on etcd.
We’ve already created a Key Vault. We shall use that Key Vault to create a key used for KMS purposes.
We will create a key first:
resource "azurerm_key_vault_key" "ksm_encryption_key" { name = "ksm-encryption-key" key_vault_id = azurerm_key_vault.ksm_key_vault.id key_type = "RSA" key_size = 2048 key_opts = [ "decrypt", "encrypt", "sign", "unwrapKey", "verify", ...