-
Notifications
You must be signed in to change notification settings - Fork 488
Open
Labels
Class: Resource Module 📦This is a resource moduleThis is a resource moduleType: AVM 🅰️ ✌️ Ⓜ️This is an AVM related issueThis is an AVM related issueType: Feature Request ➕New feature or requestNew feature or request
Description
Check for previous/existing GitHub issues
- I have checked for previous/existing GitHub issues
Issue Type?
Feature Request
Module Name
avm/res/document-db/database-account
(Optional) Module Version
0.8.1
Description
Description
In CosmosDB Account AVM, it is not possible to set customer-managed key for encryption.
Following properties are missing:
- keyVaultKeyUri - The URI of the key vault
- defaultIdentity - The default identity for accessing key vault used in features like customer managed keys. The default identity needs to be explicitly set by the users. It can be "FirstPartyIdentity", "SystemAssignedIdentity" and more.
See plain Bicep: https://learn.microsoft.com/en-us/azure/templates/Microsoft.DocumentDB/2023-04-15/databaseAccounts?pivots=deployment-language-bicep
This would enable direct encryption of CosmosDB Account with CMK.
(Optional) Correlation Id
No response
jhueppauff and KleivardJonathan
Metadata
Metadata
Assignees
Labels
Class: Resource Module 📦This is a resource moduleThis is a resource moduleType: AVM 🅰️ ✌️ Ⓜ️This is an AVM related issueThis is an AVM related issueType: Feature Request ➕New feature or requestNew feature or request
Type
Projects
Status
In Active Discussion