005. ADR: Key Vault Configuration Assessment and Recommendations
Date: 20-03-2025
State: Proposed/Accepted/Deprecated/Superseded
Status: Approved
Context
The development instance currently has 17 deployed Key Vaults. Some of these are related to OSDU, while others serve different teams or test purposes. There are challenges with managing secrets for application registrations, inconsistent naming conventions, and the presence of unnecessary or outdated test vaults. The current setup also lacks certain best practices regarding access control, network security, and monitoring.
| Key Vault Name | Resource Group | Location | Subscription |
|---|---|---|---|
| di-common-dev-vault001 | configuration-rg | West Europe | S448-OSDU-Dev |
| di-diskos-dev-keyvault | di-diskos | West Europe | S448-OSDU-Dev |
| di-scm-dev-vault001 | di-scm | West Europe | S448-OSDU-Dev |
| di-seismeta-dev-vault | di-seismeta | West Europe | S448-OSDU-Dev |
| di-seismic-file-dev-kv | di-seismic-file | West Europe | S448-OSDU-Dev |
| di-smda-dev-vault | di-smda | West Europe | S448-OSDU-Dev |
| dlz-dev-vault003 | dlz-logging-rg | West Europe | S448-OSDU-Dev |
| equinordev | osdu-rg | West Europe | S448-OSDU-Dev |
| fileingest-dev-vault | di-welldb-file-ingestor | West Europe | S448-OSDU-Dev |
| fjlan-test2 | fjlan-test | West Europe | S448-OSDU-Dev |
| gczsec | gcz-rg | West Europe | S448-OSDU-Dev |
| osdu-aks-kv | osdu-aks-rg | West Europe | S448-OSDU-Dev |
| osdu-credentials-test | osdu-rg | West Europe | S448-OSDU-Dev |
| osdu-fabric-kv | rg-fabric | West Europe | S448-OSDU-Dev |
| Rddms | osdu-rg | West Europe | S448-OSDU-Dev |
| sdbdiskosreportkeyvault | sdbdiskosreporting | West Europe | S448-OSDU-Dev |
| wle-dev-vault | di-wle-file-ingestor | West Europe | S448-OSDU-Dev |
Decision
We have agreed to implement the following recommendations for improving Key Vault configuration management:
-
Migrate Application Registration Secrets to Key Vaults: Store all required application registration secrets in Azure Key Vault to enhance security and simplify management. App Registrations that we deal with:
- osdu-cli
- osdu-docs
- osdu-health
- osdu-ssp-np
- osdu-token-creator (Does not need to be migrated to Key Vault. These are personal tokens)
- osdu-token-service
-
Assess and Transition Non-OSDU Key Vaults: Identify and evaluate Key Vaults serving non-OSDU groups and transition them out of the current subscription or decommission them if no longer needed.
-
Establish Naming Convention Standards: Develop and enforce a consistent naming convention for all Key Vaults to improve clarity and management. Review existing Key Vault names and modify them to align with the standards. Refer to ADR 006. ADR: Standardised Naming Conventions for Resource Groups and Resources
-
Review and Remove Personal Testing Key Vaults: Identify and evaluate Key Vaults created for personal testing. Delete any that are no longer necessary to reduce clutter and minimize security risks.
-
Implement Best Practices:
- Access Control: Implement Role-Based Access Control (RBAC) to ensure that only authorized users and applications have access to specific Key Vaults and their contents.
- Network Security: Configure network restrictions to limit Key Vault access to trusted networks and applications.
- Data Protection: Enable soft delete and purge protection to prevent accidental or malicious deletion of Key Vaults.
- Monitoring and Logging: Set up diagnostic logging and alerts to monitor access and operations performed on Key Vaults.
-
Enable PIM to create secrects: To create a secret, users should be required to use Privileged Identity Management (PIM) to obtain the Key Vault Officer role. PIM access should be linked to access groups rather than individual users.
-
Require Owner Tag for secrets: Ensure that an owner tag, including the email address of the individual who created the secret, is added. This will facilitate easier tracking of the secret's origin.
-
One Key Vault Per Environment: One key vault per environment per respurce group following the microsoft recommendations.
These actions will improve security, streamline management, and enhance the overall effectiveness of the Key Vault configuration.
Consequences
By following these recommendations:
- Security will be improved by ensuring that sensitive application secrets are securely stored in Key Vaults.
- Management will be simplified through the transition of non-OSDU Key Vaults and the elimination of outdated or unnecessary test vaults.
- Operational clarity will be enhanced by enforcing consistent naming conventions.
- Access control and security will be strengthened by implementing RBAC and network restrictions.
- Monitoring and auditing capabilities will be improved, helping to detect and mitigate suspicious activities.
These improvements will lead to better security practices, streamlined resource management, and a more manageable Key Vault environment across development, test, and production instances.