KMS Keys
Use KMS keys for resource encryption
Last updated
Was this helpful?
Use KMS keys for resource encryption
DuploCloud allows you to configure Tenant and Plan level KMS (Key Management Service) keys for AWS/Azure resources. These keys can be selected when creating supported resources to ensure consistent encryption and help meet compliance requirements.
Plan-level KMS keys can be used for encrypting resources in any Tenant under the selected Plan.
Navigate to Administrator -> Plans.
Select the Plan from the NAME column.
Select the KMS tab.
Click Add. The Add a Kms Key pane displays.

Complete the following fields:
Key Name
Enter a friendly name for the key (e.g., test-key)
Key Id
Enter the cloud provider–specific key ID (AWS KMS Key ID or Azure Key Vault Key ID).
Key Arn
Enter the cloud provider–specific key ARN or resource ID. For AWS this is the KMS Key ARN; for Azure, this is the Key Vault Key ID URI.
Click Submit to add the key to the Plan. Once added, the key can be selected when creating supported resources in the Plan, such as databases, compute instances, storage resources, and other services.

Tenant-level KMS keys can be used for encrypting resources only within the selected tenant.
Navigate to Administrator -> Tenants.
Select the Tenant from the NAME column.
Select the KMS tab.
Click Add. The Add a Kms Key pane displays.

Complete the following fields:
Key Name
Enter a friendly name for the key (e.g., test-key)
Key Id
Enter the cloud provider–specific key ID (AWS KMS Key ID or Azure Key Vault Key ID).
Key Arn
Enter the cloud provider–specific key ARN or resource ID. For AWS this is the KMS Key ARN; for Azure, this is the Key Vault Key ID URI.
Click Submit to add the key to the Tenant. Once added, the key can be selected when creating supported resources in the Tenant.

When creating a Host, RDS database, or other supported resource, select a KMS key to use for encrypting data at rest.
Navigate to the resource creation page (e.g., Hosts, RDS, or other supported resources).
Locate the Encryption Key or KMS Key field.
Choose a key from the options listed under Default Tenant Key, Plan-level Keys, or Tenant-level Keys.

Complete the rest of the resource creation steps as usual.
Note: Only applicable resources will display these key options. Unsupported resources will continue to use the default tenant key.
Last updated
Was this helpful?
Was this helpful?

