keyvault.azure.com/v20230701
APIVersion
| Value | Description |
|---|---|
| “2023-07-01” |
VaultKey
Generator information:
- Generated from: /keyvault/resource-manager/Microsoft.KeyVault/KeyVault/stable/2023-07-01/keys.json
- ARM URI: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.KeyVault/vaults/{vaultName}/keys/{keyName}
Used by: VaultKeyList.
| Property | Description | Type |
|---|---|---|
| metav1.TypeMeta | ||
| metav1.ObjectMeta | ||
| spec | VaultKey_Spec Optional |
|
| status | VaultKey_STATUS Optional |
VaultKey_Spec
| Property | Description | Type |
|---|---|---|
| azureName | The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. | string Optional |
| operatorSpec | The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure | VaultKeyOperatorSpec Optional |
| owner | The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a keyvault.azure.com/Vault resource | genruntime.KnownResourceReference Required |
| properties | The properties of the key to be created. | KeyProperties Required |
| tags | The tags that will be assigned to the key. | map[string]string Optional |
VaultKey_STATUS
| Property | Description | Type |
|---|---|---|
| attributes | The attributes of the key. | KeyAttributes_STATUS Optional |
| conditions | The observed state of the resource | conditions.Condition[] Optional |
| curveName | The elliptic curve name. For valid values, see JsonWebKeyCurveName. | KeyProperties_CurveName_STATUS Optional |
| id | Fully qualified identifier of the key vault resource. | string Optional |
| keyOps | KeyProperties_KeyOps_STATUS[] Optional |
|
| keySize | The key size in bits. For example: 2048, 3072, or 4096 for RSA. | int Optional |
| keyUri | The URI to retrieve the current version of the key. | string Optional |
| keyUriWithVersion | The URI to retrieve the specific version of the key. | string Optional |
| kty | The type of the key. For valid values, see JsonWebKeyType. | KeyProperties_Kty_STATUS Optional |
| location | Azure location of the key vault resource. | string Optional |
| name | Name of the key vault resource. | string Optional |
| release_policy | Key release policy in response. It will be used for both output and input. Omitted if empty | KeyReleasePolicy_STATUS Optional |
| rotationPolicy | Key rotation policy in response. It will be used for both output and input. Omitted if empty | RotationPolicy_STATUS Optional |
| tags | Tags assigned to the key vault resource. | map[string]string Optional |
| type | Resource type of the key vault resource. | string Optional |
VaultKeyList
Generator information:
- Generated from: /keyvault/resource-manager/Microsoft.KeyVault/KeyVault/stable/2023-07-01/keys.json
- ARM URI: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.KeyVault/vaults/{vaultName}/keys/{keyName}
| Property | Description | Type |
|---|---|---|
| metav1.TypeMeta | ||
| metav1.ListMeta | ||
| items | VaultKey[] Optional |
VaultKey_Spec
Used by: VaultKey.
| Property | Description | Type |
|---|---|---|
| azureName | The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. | string Optional |
| operatorSpec | The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure | VaultKeyOperatorSpec Optional |
| owner | The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a keyvault.azure.com/Vault resource | genruntime.KnownResourceReference Required |
| properties | The properties of the key to be created. | KeyProperties Required |
| tags | The tags that will be assigned to the key. | map[string]string Optional |
VaultKey_STATUS
Used by: VaultKey.
| Property | Description | Type |
|---|---|---|
| attributes | The attributes of the key. | KeyAttributes_STATUS Optional |
| conditions | The observed state of the resource | conditions.Condition[] Optional |
| curveName | The elliptic curve name. For valid values, see JsonWebKeyCurveName. | KeyProperties_CurveName_STATUS Optional |
| id | Fully qualified identifier of the key vault resource. | string Optional |
| keyOps | KeyProperties_KeyOps_STATUS[] Optional |
|
| keySize | The key size in bits. For example: 2048, 3072, or 4096 for RSA. | int Optional |
| keyUri | The URI to retrieve the current version of the key. | string Optional |
| keyUriWithVersion | The URI to retrieve the specific version of the key. | string Optional |
| kty | The type of the key. For valid values, see JsonWebKeyType. | KeyProperties_Kty_STATUS Optional |
| location | Azure location of the key vault resource. | string Optional |
| name | Name of the key vault resource. | string Optional |
| release_policy | Key release policy in response. It will be used for both output and input. Omitted if empty | KeyReleasePolicy_STATUS Optional |
| rotationPolicy | Key rotation policy in response. It will be used for both output and input. Omitted if empty | RotationPolicy_STATUS Optional |
| tags | Tags assigned to the key vault resource. | map[string]string Optional |
| type | Resource type of the key vault resource. | string Optional |
KeyAttributes_STATUS
The object attributes managed by the Azure Key Vault service.
Used by: VaultKey_STATUS.
| Property | Description | Type |
|---|---|---|
| created | Creation time in seconds since 1970-01-01T00:00:00Z. | int Optional |
| enabled | Determines whether or not the object is enabled. | bool Optional |
| exp | Expiry date in seconds since 1970-01-01T00:00:00Z. | int Optional |
| exportable | Indicates if the private key can be exported. | bool Optional |
| nbf | Not before date in seconds since 1970-01-01T00:00:00Z. | int Optional |
| recoveryLevel | The deletion recovery level currently in effect for the object. If it contains Purgeable, then the object can be permanently deleted by a privileged user; otherwise, only the system can purge the object at the end of the retention interval. |
KeyAttributes_RecoveryLevel_STATUS Optional |
| updated | Last updated time in seconds since 1970-01-01T00:00:00Z. | int Optional |
KeyProperties
The properties of the key.
Used by: VaultKey_Spec.
| Property | Description | Type |
|---|---|---|
| attributes | The attributes of the key. | KeyAttributes Optional |
| curveName | The elliptic curve name. For valid values, see JsonWebKeyCurveName. | KeyProperties_CurveName Optional |
| keyOps | KeyProperties_KeyOps[] Optional |
|
| keySize | The key size in bits. For example: 2048, 3072, or 4096 for RSA. | int Optional |
| kty | The type of the key. For valid values, see JsonWebKeyType. | KeyProperties_Kty Optional |
| release_policy | Key release policy in response. It will be used for both output and input. Omitted if empty | KeyReleasePolicy Optional |
| rotationPolicy | Key rotation policy in response. It will be used for both output and input. Omitted if empty | RotationPolicy Optional |
KeyProperties_CurveName_STATUS
Used by: VaultKey_STATUS.
| Value | Description |
|---|---|
| “P-256” | |
| “P-256K” | |
| “P-384” | |
| “P-521” |
KeyProperties_KeyOps_STATUS
Used by: VaultKey_STATUS.
| Value | Description |
|---|---|
| “decrypt” | |
| “encrypt” | |
| “import” | |
| “release” | |
| “sign” | |
| “unwrapKey” | |
| “verify” | |
| “wrapKey” |
KeyProperties_Kty_STATUS
Used by: VaultKey_STATUS.
| Value | Description |
|---|---|
| “EC” | |
| “EC-HSM” | |
| “RSA” | |
| “RSA-HSM” |
KeyReleasePolicy_STATUS
Used by: VaultKey_STATUS.
| Property | Description | Type |
|---|---|---|
| contentType | Content type and version of key release policy | string Optional |
| data | Blob encoding the policy rules under which the key can be released. | string Optional |
RotationPolicy_STATUS
Used by: VaultKey_STATUS.
| Property | Description | Type |
|---|---|---|
| attributes | The attributes of key rotation policy. | KeyRotationPolicyAttributes_STATUS Optional |
| lifetimeActions | The lifetimeActions for key rotation action. | LifetimeAction_STATUS[] Optional |
VaultKeyOperatorSpec
Details for configuring operator behavior. Fields in this struct are interpreted by the operator directly rather than being passed to Azure
Used by: VaultKey_Spec.
| Property | Description | Type |
|---|---|---|
| configMapExpressions | configures where to place operator written dynamic ConfigMaps (created with CEL expressions). | core.DestinationExpression[] Optional |
| createMode | Specifies how the operator handles a soft-deleted key occupying the requested name at creation time. default issues a plain create and surfaces the Azure conflict error if a soft-deleted key blocks the name; recover recovers the soft-deleted key and fails when none exists; createOrRecover recovers a soft-deleted key when one exists and otherwise creates a new key; purgeThenCreate permanently purges the soft-deleted key before creating a replacement. Defaults to default. |
string Optional |
| deleteMode | Specifies what happens to the key in Azure when the VaultKey resource is deleted from Kubernetes. detach leaves the key untouched in the vault; delete soft-deletes the key via the Key Vault data plane; disable sets the key’s enabled attribute to false and leaves it in the vault. Defaults to detach, which preserves the key. |
string Optional |
| secretExpressions | configures where to place operator written dynamic secrets (created with CEL expressions). | core.DestinationExpression[] Optional |
KeyAttributes
The object attributes managed by the Azure Key Vault service.
Used by: KeyProperties.
| Property | Description | Type |
|---|---|---|
| enabled | Determines whether or not the object is enabled. | bool Optional |
| exp | Expiry date in seconds since 1970-01-01T00:00:00Z. | int Optional |
| exportable | Indicates if the private key can be exported. | bool Optional |
| nbf | Not before date in seconds since 1970-01-01T00:00:00Z. | int Optional |
KeyAttributes_RecoveryLevel_STATUS
Used by: KeyAttributes_STATUS.
| Value | Description |
|---|---|
| “Purgeable” | |
| “Recoverable” | |
| “Recoverable+ProtectedSubscription” | |
| “Recoverable+Purgeable” |
KeyProperties_CurveName
Used by: KeyProperties.
| Value | Description |
|---|---|
| “P-256” | |
| “P-256K” | |
| “P-384” | |
| “P-521” |
KeyProperties_KeyOps
Used by: KeyProperties.
| Value | Description |
|---|---|
| “decrypt” | |
| “encrypt” | |
| “import” | |
| “release” | |
| “sign” | |
| “unwrapKey” | |
| “verify” | |
| “wrapKey” |
KeyProperties_Kty
Used by: KeyProperties.
| Value | Description |
|---|---|
| “EC” | |
| “EC-HSM” | |
| “RSA” | |
| “RSA-HSM” |
KeyReleasePolicy
Used by: KeyProperties.
| Property | Description | Type |
|---|---|---|
| contentType | Content type and version of key release policy | string Optional |
| data | Blob encoding the policy rules under which the key can be released. | string Optional |
KeyRotationPolicyAttributes_STATUS
Used by: RotationPolicy_STATUS.
| Property | Description | Type |
|---|---|---|
| created | Creation time in seconds since 1970-01-01T00:00:00Z. | int Optional |
| expiryTime | The expiration time for the new key version. It should be in ISO8601 format. Eg: P90D, P1Y. |
string Optional |
| updated | Last updated time in seconds since 1970-01-01T00:00:00Z. | int Optional |
LifetimeAction_STATUS
Used by: RotationPolicy_STATUS.
| Property | Description | Type |
|---|---|---|
| action | The action of key rotation policy lifetimeAction. | Action_STATUS Optional |
| trigger | The trigger of key rotation policy lifetimeAction. | Trigger_STATUS Optional |
RotationPolicy
Used by: KeyProperties.
| Property | Description | Type |
|---|---|---|
| attributes | The attributes of key rotation policy. | KeyRotationPolicyAttributes Optional |
| lifetimeActions | The lifetimeActions for key rotation action. | LifetimeAction[] Optional |
Action_STATUS
Used by: LifetimeAction_STATUS.
| Property | Description | Type |
|---|---|---|
| type | The type of action. | Action_Type_STATUS Optional |
KeyRotationPolicyAttributes
Used by: RotationPolicy.
| Property | Description | Type |
|---|---|---|
| expiryTime | The expiration time for the new key version. It should be in ISO8601 format. Eg: P90D, P1Y. |
string Optional |
LifetimeAction
Used by: RotationPolicy.
| Property | Description | Type |
|---|---|---|
| action | The action of key rotation policy lifetimeAction. | Action Optional |
| trigger | The trigger of key rotation policy lifetimeAction. | Trigger Optional |
Trigger_STATUS
Used by: LifetimeAction_STATUS.
| Property | Description | Type |
|---|---|---|
| timeAfterCreate | The time duration after key creation to rotate the key. It only applies to rotate. It will be in ISO 8601 duration format. Eg: P90D, P1Y. |
string Optional |
| timeBeforeExpiry | The time duration before key expiring to rotate or notify. It will be in ISO 8601 duration format. Eg: P90D, P1Y. |
string Optional |
Action
Used by: LifetimeAction.
| Property | Description | Type |
|---|---|---|
| type | The type of action. | Action_Type Optional |
Action_Type_STATUS
Used by: Action_STATUS.
| Value | Description |
|---|---|
| “notify” | |
| “rotate” |
Trigger
Used by: LifetimeAction.
| Property | Description | Type |
|---|---|---|
| timeAfterCreate | The time duration after key creation to rotate the key. It only applies to rotate. It will be in ISO 8601 duration format. Eg: P90D, P1Y. |
string Optional |
| timeBeforeExpiry | The time duration before key expiring to rotate or notify. It will be in ISO 8601 duration format. Eg: P90D, P1Y. |
string Optional |
Action_Type
Used by: Action.
| Value | Description |
|---|---|
| “notify” | |
| “rotate” |