Legacy AKS plug-in using an Azure Key Vault key to encrypt Kubernetes Secrets at rest in etcd. On Kubernetes 1.33 onwards, Microsoft Learn points to the newer KMS data encryption experience instead.
Also called Key Management Service.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains KMS in context, with comparison tables and the common traps.
Terms in this definition
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
- Azure Key Vault
Azure service holding secrets, keys and certificates. If the region has a paired region in the same geography, contents replicate to it, and during a best-effort failover initiated by Microsoft the vault can only be read.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - REST
Short for representational state transfer, the style of HTTP API that Azure services expose.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
Related terms
- Standard key provider
Uses an outside KMIP key management server as the source of encryption keys for vCenter. Since vSphere 9.0, wrapped key mode is the default, so many keys sit under a single wrapping key held by the KMS (the Native Key Provider needs no KMS at all).
- vSphere Native Key Provider
Built into vCenter, this provider generates encryption keys itself, so no external KMS is needed; back it up before first use.