Description
A Key Vault secret’s expiration date is metadata for credential lifecycle management. Setting it does not rotate or revoke the password or API key in the issuing service.
Potential impact
Without scheduled replacement and consumer updates, old credentials can remain valid or service connections can break during a change.
Remediation
Set expiration_date and replace the credential in the issuing service before expiry. Update consumers, then revoke the old credential.
Examples
The examples add an expiration date to an illustrative secret. Choose a date that matches the actual replacement plan.
Before
hcl
resource "azurerm_key_vault_secret" "example" {
name = "secret-sauce"
value = "szechuan"
key_vault_id = azurerm_key_vault.example.id
tags = {
environment = "Production"
}
}
After
hcl
resource "azurerm_key_vault_secret" "example" {
name = "secret-sauce"
value = "szechuan"
key_vault_id = azurerm_key_vault.example.id
tags = {
environment = "Production"
}
expiration_date = "2026-12-30T20:00:00Z"
}