Bring Your Own Key (BYOK) for Encryption at Rest
Implement encryption at rest with Azure Key Vault and Elastic Cloud

Implement encryption at rest with Azure Key Vault and Elastic Cloud

8/20/2024

What this post added

This post details the technical implementation of BYOK for encryption at rest specifically for Elastic Cloud deployments on Microsoft Azure, using Azure Key Vault. It outlines the architecture, prerequisites (Enterprise subscription, RSA key creation in Azure Key Vault, IAM policies), the step-by-step process of creating an Azure Key Vault key and configuring it with an Elastic Cloud deployment, and verification methods. It also touches upon key rotation and revocation within the Azure Key Vault context.

Read the original post ↗