Review Key Vault key expiration

Manage key lifetimes and replacement schedules explicitly.

Description

A Key Vault key’s expiration date supports lifecycle management. Without an expiry date, a key can remain in use beyond the organization’s intended lifetime.

Potential impact

Missed replacement deadlines can leave old keys in use or cause an unplanned expiry to interrupt services.

Remediation

Set expiration_date to match the intended lifetime and move consumers to a replacement key before expiry. Configure a separate rotation policy if automatic rotation is required.

Examples

The examples add an expiration date. Choose a date that matches the actual replacement schedule instead of copying the illustrated value.

Before

hcl
resource "azurerm_key_vault_key" "example" {
  name         = "generated-certificate"
  key_vault_id = azurerm_key_vault.example.id
  key_type     = "RSA"
  key_size     = 2048

  key_opts = [
    "decrypt",
    "encrypt",
    "sign",
    "unwrapKey",
    "verify",
    "wrapKey",
  ]
}

After

hcl
resource "azurerm_key_vault_key" "example" {
  name         = "generated-certificate"
  key_vault_id = azurerm_key_vault.example.id
  key_type     = "RSA"
  key_size     = 2048

  key_opts = [
    "decrypt",
    "encrypt",
    "sign",
    "unwrapKey",
    "verify",
    "wrapKey",
  ]

  expiration_date = "2026-12-30T20:00:00Z"
}

References