-
Notifications
You must be signed in to change notification settings - Fork 4.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support Data encryption for Azure Database for PostgreSQL (BYOK) #7811
Comments
We're currently exploring setting this up manually and noticed that the Postgres server also needs a Managed Identity connected to if in order to access the Keyvault. I currently don't see an option in the TF module to do this. Would this be handled automatically by the Azure RM? If so, we still need the ID / name of the Managed Identity to setup the Keyvault access policies correctly. |
@pietervincken Doesn't the managed identity part work with: resource "azurerm_postgresql_server" "example" {
...
identity {
type = SystemAssigned
}
} and then use it as: resource "azurerm_key_vault_access_policy" "example_policy" {
key_vault_id = azurerm_key_vault.example.id
[...]
object_id = azurerm_postgresql_server.example.identity.principal_id
} ? |
@flo-02-mu You are completely right. I totally missed that in the documentation somehow 🤦 Sorry about that. |
Adding customer managed key support for postgreSQL Server Fixes #7811
This has been released in version 2.29.0 of the provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading. As an example: provider "azurerm" {
version = "~> 2.29.0"
}
# ... other configuration ... |
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. If you feel this issue should be reopened, we encourage creating a new issue linking back to this one for added context. If you feel I made an error 🤖 🙉 , please reach out to my human friends 👉 [email protected]. Thanks! |
Community Note
Description
Azure recently has announced the Data encryption for it's PostgreSQL database.
Would be nice if Terraform will support this too.
https://docs.microsoft.com/en-us/azure/postgresql/howto-data-encryption-cli
New or Affected Resource(s)
Potential Terraform Configuration
References
The text was updated successfully, but these errors were encountered: