Skip to content

005. ADR: Key Vault Configuration Assessment and Recommendations

Date: 20-03-2025

State: Proposed/Accepted/Deprecated/Superseded

Status: Approved

Context

The development instance currently has 17 deployed Key Vaults. Some of these are related to OSDU, while others serve different teams or test purposes. There are challenges with managing secrets for application registrations, inconsistent naming conventions, and the presence of unnecessary or outdated test vaults. The current setup also lacks certain best practices regarding access control, network security, and monitoring.

Key Vault Name Resource Group Location Subscription
di-common-dev-vault001 configuration-rg West Europe S448-OSDU-Dev
di-diskos-dev-keyvault di-diskos West Europe S448-OSDU-Dev
di-scm-dev-vault001 di-scm West Europe S448-OSDU-Dev
di-seismeta-dev-vault di-seismeta West Europe S448-OSDU-Dev
di-seismic-file-dev-kv di-seismic-file West Europe S448-OSDU-Dev
di-smda-dev-vault di-smda West Europe S448-OSDU-Dev
dlz-dev-vault003 dlz-logging-rg West Europe S448-OSDU-Dev
equinordev osdu-rg West Europe S448-OSDU-Dev
fileingest-dev-vault di-welldb-file-ingestor West Europe S448-OSDU-Dev
fjlan-test2 fjlan-test West Europe S448-OSDU-Dev
gczsec gcz-rg West Europe S448-OSDU-Dev
osdu-aks-kv osdu-aks-rg West Europe S448-OSDU-Dev
osdu-credentials-test osdu-rg West Europe S448-OSDU-Dev
osdu-fabric-kv rg-fabric West Europe S448-OSDU-Dev
Rddms osdu-rg West Europe S448-OSDU-Dev
sdbdiskosreportkeyvault sdbdiskosreporting West Europe S448-OSDU-Dev
wle-dev-vault di-wle-file-ingestor West Europe S448-OSDU-Dev

Decision

We have agreed to implement the following recommendations for improving Key Vault configuration management:

  1. Migrate Application Registration Secrets to Key Vaults: Store all required application registration secrets in Azure Key Vault to enhance security and simplify management. App Registrations that we deal with:

    • osdu-cli
    • osdu-docs
    • osdu-health
    • osdu-ssp-np
    • osdu-token-creator (Does not need to be migrated to Key Vault. These are personal tokens)
    • osdu-token-service
  2. Assess and Transition Non-OSDU Key Vaults: Identify and evaluate Key Vaults serving non-OSDU groups and transition them out of the current subscription or decommission them if no longer needed.

  3. Establish Naming Convention Standards: Develop and enforce a consistent naming convention for all Key Vaults to improve clarity and management. Review existing Key Vault names and modify them to align with the standards. Refer to ADR 006. ADR: Standardised Naming Conventions for Resource Groups and Resources

  4. Review and Remove Personal Testing Key Vaults: Identify and evaluate Key Vaults created for personal testing. Delete any that are no longer necessary to reduce clutter and minimize security risks.

  5. Implement Best Practices:

    • Access Control: Implement Role-Based Access Control (RBAC) to ensure that only authorized users and applications have access to specific Key Vaults and their contents.
    • Network Security: Configure network restrictions to limit Key Vault access to trusted networks and applications.
    • Data Protection: Enable soft delete and purge protection to prevent accidental or malicious deletion of Key Vaults.
    • Monitoring and Logging: Set up diagnostic logging and alerts to monitor access and operations performed on Key Vaults.
  6. Enable PIM to create secrects: To create a secret, users should be required to use Privileged Identity Management (PIM) to obtain the Key Vault Officer role. PIM access should be linked to access groups rather than individual users.

  7. Require Owner Tag for secrets: Ensure that an owner tag, including the email address of the individual who created the secret, is added. This will facilitate easier tracking of the secret's origin.

  8. One Key Vault Per Environment: One key vault per environment per respurce group following the microsoft recommendations.

These actions will improve security, streamline management, and enhance the overall effectiveness of the Key Vault configuration.

Consequences

By following these recommendations:

  • Security will be improved by ensuring that sensitive application secrets are securely stored in Key Vaults.
  • Management will be simplified through the transition of non-OSDU Key Vaults and the elimination of outdated or unnecessary test vaults.
  • Operational clarity will be enhanced by enforcing consistent naming conventions.
  • Access control and security will be strengthened by implementing RBAC and network restrictions.
  • Monitoring and auditing capabilities will be improved, helping to detect and mitigate suspicious activities.

These improvements will lead to better security practices, streamlined resource management, and a more manageable Key Vault environment across development, test, and production instances.


Last update: 2026-09-14