Create a vault
Create a vault in a resource group, choose its protection settings, and decide who can read it.
Requires: secretvault/write
Creating a vault needs the secretvault/write permission in the resource group; the Owner
and Contributor roles have it.
Open the wizard
In the portal at https://portal.example.com, open Secret Vaults in the sidebar and choose Create Secret Vaults. The Create Secret Vault wizard has three steps.
Name and placement
The Basics step asks for:
- Vault Name — lowercase letters, digits and hyphens, 3 to 50 characters, not starting or ending with a hyphen. The name is the vault's address, so it must be unique across the whole platform; a name that is already taken is refused when you create the vault.
- Boundary, Cluster and Resource group — where the vault lives. Each is filled in for you when there is only one choice.
Protection settings
The Vault Configuration step sets how deleted secrets are to be protected:
- Enable Soft Delete — on by default — with a Retention Period of 7 to 90 days (default 90).
- Enable Purge Protection — off by default.
Important
These settings are stored on the vault but not applied yet. Every deleted secret is kept for 90 days whatever they say, and deleting the vault itself is always permanent. See Delete, recover and purge.
Review and create
Review & Create shows the name, resource group and protection settings. Create the vault; it is ready when its status is Ready, and its Overview then shows the Vault URI.
With the CLI:
stsh vault create my-vault -g my-resource-group -c my-clusterAnyone with Reader on its resource group or boundary can then look the vault up through the API:
GET https://api.example.com/boundaries/<boundary-id>/resourcegroups/my-resource-group/resources/secretvaults/my-vaultWho can read it
A new vault grants nobody anything new. People and workloads use it through roles assigned on its boundary, its resource group or the vault itself (Access Control):
- Secrets Reader reads secret values.
- Secrets Writer also creates, changes and deletes secrets.
- Owner and Contributor can do both; Reader sees the vault and the names of its secrets, but no values.
A workload needs Secrets Reader on the vault before it can start with a secret from it — see Give a workload access. All roles and actions are listed in Permissions.