Review Key Vault secret expiration

Schedule credential replacement and update its consumers.

Description

A Key Vault secret’s expiration date is metadata for credential lifecycle management. Setting it does not rotate or revoke the password or API key in the issuing service.

Potential impact

Without scheduled replacement and consumer updates, old credentials can remain valid or service connections can break during a change.

Remediation

Set expiration_date and replace the credential in the issuing service before expiry. Update consumers, then revoke the old credential.

Examples

The examples add an expiration date to an illustrative secret. Choose a date that matches the actual replacement plan.

Before

hcl
resource "azurerm_key_vault_secret" "example" {
  name         = "secret-sauce"
  value        = "szechuan"
  key_vault_id = azurerm_key_vault.example.id

  tags = {
    environment = "Production"
  }
}

After

hcl
resource "azurerm_key_vault_secret" "example" {
  name         = "secret-sauce"
  value        = "szechuan"
  key_vault_id = azurerm_key_vault.example.id

  tags = {
    environment = "Production"
  }

  expiration_date = "2026-12-30T20:00:00Z"
}

References