Loading...

GA: Azure Key Vault secrets provider extension for Arc enabled Kubernetes clusters

GA: Azure Key Vault secrets provider extension for Arc enabled Kubernetes clusters

The Azure Arc team is happy to announce the GA of Azure Key Vault Secrets Provider extension for Arc enabled Kubernetes clusters. This is a Microsoft managed extension that allows you to get secret contents stored in an Azure Key Vault instance and mount them into Kubernetes pods of your Azure Arc enabled Kubernetes clusters, thereby reducing the exposure of secrets to the minimum. It can pull any type of object from an Azure Key Vault, including keys, secrets and certificates.

 

The extension is installed by a cluster admin. With the installation, Secrets Store CSI driver and AKV secrets provider are deployed as daemon sets. On application pod start and restart, the Secrets Store CSI driver communicates with the Azure Key Vault secrets provider using gRPC to retrieve the secret content from the Azure Key Vault.  Then the volume is mounted in the pod as tmpfs and the secret contents are written to the volume. On pod delete, the corresponding volume is cleaned up and deleted.

 

CSI driver Interface.png

 

This extension can be deployed using az k8s-extension CLI and also using Azure Portal. For deployment through portal, go to the Arc connected Kubernetes cluster and click on Extensions under Settings. Further, click on +Add to add Azure Key Vault Secrets Provider extension. Check out the full documentation on how to enable it for an Arc enabled Kubernetes cluster. 

 

The extension allows for 3 configuration options:

  1. Secret Rotation - Periodically update the pod mount with the latest secret from the AKV secrets store. The polling of latest secret does not require pod restart. It is disabled by default.
  2. Rotation Poll Interval - Frequency of the pod mount update if Secret Rotation configuration is enabled. The default is 2 minutes.
  3. Sync as Kubernetes secret - Create Kubernetes secret(s) to mirror the mounted content. It is disabled by default.

A service principal is required to enable the access to Azure Key Vault from within the Arc cluster. Further, a Kubernetes secret needs to be created in the application namespace that references this service principal in order to gain access to the vault. 

 

What next?

The identity option available today is service principal. However, we are investing in using workload identity as another option in future.

 

Learn more at the Azure Hybrid, Multicloud, and Edge Day digital event

We will be hosting our annual Azure Hybrid, Multicloud, and Edge Day digital event on June 15, 2022. You’ll hear from Microsoft leadership and engineers on how you can innovate anywhere with Azure Arc, learn from customers using Azure solutions for their hybrid scenarios, and get to ask questions in the live Q&A chat. Register now >

Published on:

Learn more
Azure Arc Blog articles
Azure Arc Blog articles

Azure Arc Blog articles

Share post:

Related posts

How Microsoft Fabric, Azure, and Power BI Are Transforming Analytics

Introduction Data has become one of the most valuable assets for modern organisations. However, collecting data alone is no longer enough—busi...

2 days ago

Top Azure Services Every Dynamics 365 Developer Must Learn

Introduction Microsoft Dynamics 365 has evolved far beyond being just a Customer Relationship Management (CRM) or Enterprise Resource Planning...

4 days ago

Creating AI-Powered Workflows Using Power Automate and Azure AI

Introduction Artificial Intelligence is revolutionising business automation by enabling organisations to build workflows that not only automat...

5 days ago

Azure Developer CLI (azd) July 2026

This is the July round-up for the Azure Developer CLI (azd). Five releases shipped since the last post: 1.27.0, 1.27.1, 1.28.0, 1.28.1, and 1....

5 days ago

Azure vs AWS: Which Cloud Platform Should You Learn in 2026?

Introduction Cloud computing has become the foundation of modern digital transformation. From startups to Fortune 500 companies, organizations...

6 days ago

Building Enterprise Applications with .NET 10 and Azure Cloud

Introduction As businesses continue their digital transformation journey, enterprise applications are expected to be more intelligent, scalabl...

6 days ago

Azure Tops $100 Billion As Microsoft Reports FY26 Q4 Results

On July 29, Microsoft released their FY26 Q4 results. We learned that Microsoft 365 Copilot has 30 million paid seats, but that's still less t...

6 days ago

Azure SDK Release (July 2026)

Azure SDK releases every month. In this post, you'll find this month's highlights and release notes. The post Azure SDK Release (July 2026) ap...

6 days ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy