Skip to content

Add TDE with a customer-managed Key Vault key to the SQL Database sample - #126

Draft
bryansan-local wants to merge 2 commits into
mainfrom
web-app-sql-database-tde-cmk
Draft

bryansan-local wants to merge 2 commits into
mainfrom
web-app-sql-database-tde-cmk

Conversation

@bryansan-local

@bryansan-local bryansan-local commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

The SQL Database sample only used Key Vault for a secret and a certificate. TDE with a customer-managed key is the common real use of Key Vault keys, and it covers the emulator's new Key Vault keys management plane and the SQL server keys / encryption protector APIs.

Changes

  • The SQL server gets a user-assigned identity with get/wrapKey/unwrapKey on an RSA key, set as the TDE protector with auto-rotation (Python and .NET; az CLI, Bicep, Terraform).
  • The az CLI deployment uses az resource create for the server key and protector, since az sql server key create / tde-key set reject key ids outside *.vault.azure.net, like the emulator's.
  • Terraform gets a deployer access policy, which was also missing for the secret and certificate.
  • validate.sh checks the protector and TDE state, and run-samples.sh now runs it for Terraform too.

Tests

  • All six deployments tested end to end on real Azure and on the emulator.

This branch was successfully deployed

1 active deployment
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant