Skip to content

[MOVED] feat(azure): Add Key Vault key inspection#12137

Closed
nevzheng wants to merge 6 commits into
apache:mainfrom
nevzheng:codex/kms-api-06-azure
Closed

[MOVED] feat(azure): Add Key Vault key inspection#12137
nevzheng wants to merge 6 commits into
apache:mainfrom
nevzheng:codex/kms-api-06-azure

Conversation

@nevzheng

@nevzheng nevzheng commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator

Moved to Gravitino Enterprise: datastrato/gravitino-enterprise#903. Apache issue #12131 is now limited to the provider-neutral API/SPI and named-source routing.

What changes were proposed in this pull request?

Add an Azure Key Vault provider using the official Azure SDK and DefaultAzureCredential. It validates full key URLs against the configured vault, supports latest or pinned versions, and normalizes effective enabled state and wrapKey/unwrapKey capabilities.

Why are the changes needed?

Azure key URLs, versions, validity windows, and operations require provider-specific interpretation behind the common KMS contract.

This work is now tracked in datastrato/gravitino-enterprise#903. The Apache OSS foundation remains #12132 and #12133.

Does this PR introduce any user-facing change?

Yes. It adds the azure-key-vault source type and its configuration properties.

How was this patch tested?

  • ./gradlew :bundles:azure:test -PskipITs

Migration

@nevzheng

nevzheng commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator Author

Hi @roryqi and @lasdf1234 — please review this KMS API change (6/11). Previous: #12136. Next: #12138. Epic: #12131.

@nevzheng nevzheng changed the title [#12131] feat(azure): Add Key Vault key inspection [MOVED] feat(azure): Add Key Vault key inspection Jul 22, 2026
@nevzheng

Copy link
Copy Markdown
Collaborator Author

Moved to datastrato/gravitino-enterprise#903 under enterprise epic #899. Apache OSS scope remains #12132 and #12133 under #12131.

@nevzheng nevzheng closed this Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant