Skip to main content

Azure Key Vault

Publishes and manages certificates in Azure Key Vaults. Can be created manually via the Stores screen or automatically via Azure Discovery.


Create via the Stores screen

Step 1 — Provider

Select Azure Key Vault.

Step 2 — Integration

Select the Azure integration registered in Integrations.

Step 3 — Configuration

Select the target Resource Group and Key Vault. The CLM displays the vault URL for confirmation.

Step 4 — Review

Set the Repository Name (e.g. Azure KeyVault - qa4-kv-clm), confirm the settings, and click Create Repository.


Store details

After creating it, the details screen displays:

CardDescription
TotalTotal certificates in the Key Vault
ExpiringCertificates nearing expiration

Azure Integration Section (Read-only) — displays the data from the linked integration (Tenant ID, Subscription ID, Client ID). To change the account, you must create a new repository.

Key Vault Settings Section (Read-only) — displays Resource Group, Key Vault Name, and Vault URL. Automatically retrieved from Azure.

Metadata Section — editable fields for organization:

FieldDescription
TagsFree-form, comma-separated tags, e.g. production, critical, azure
OwnerName of the person responsible for the Store
DepartmentResponsible department or team

Logs and Audit Section — configure the log level (Info, Warning, and Error) and retention (default: 90 days).


Install a certificate

On the details screen, click Install Certificate, select the certificate from the inventory, and confirm. The CLM publishes the certificate to the Key Vault automatically.

The Installed Certificates list shows all certificates present in the vault with issuer, issuance date, validity, bind status, and the result of the last deploy.