Skip to content
KMS External Key Stores

KMS External Key Stores

External Key Store (XKS) operations are part of the kms IAM service, like KMS Key operations. Rules for key stores go in the same services.kms block of a policy. The key store targeted by an operation is exposed as resources.key_store.

Only check for the presence of parameters.proxy.auth.secret with has(), for example to prevent credential rotation. Never compare its value in a policy, since policies are readable by anyone with access to IAM roles. The stored secret is never exposed under resources.key_store.

create-key-store

[`POST /key-store`](https://community.exoscale.com/reference/api/kms/key-store/#create-key-store)

Create an External Key Store after validating the configured customer-managed XKS proxy.

Parameters:

  • parameters.name
  • parameters.description
  • parameters.type
  • parameters.proxy.endpoint
  • parameters.proxy.auth.key
  • parameters.proxy.auth.secret

update-key-store

[`POST /key-store/<id>/update`](https://community.exoscale.com/reference/api/kms/key-store/#update-key-store)

Updates an External Key Store with a new description, endpoint, or credentials.

Parameters:

  • parameters.id
  • parameters.description
  • parameters.proxy.endpoint
  • parameters.proxy.auth.key
  • parameters.proxy.auth.secret

Resources:

  • resources.key_store.id
  • resources.key_store.name
  • resources.key_store.description
  • resources.key_store.type
  • resources.key_store.status
  • resources.key_store.status_since
  • resources.key_store.created_at
  • resources.key_store.proxy.endpoint
  • resources.key_store.proxy.auth.key
  • resources.key_store.health.status
  • resources.key_store.health.status_reason
  • resources.key_store.health.checked_at
  • resources.key_store.health.error_detail
  • resources.key_store.health.metadata_json

list-key-stores

[`GET /key-store`](https://community.exoscale.com/reference/api/kms/key-store/#list-key-stores)

Lists all key stores configured for an organization.

get-key-store

[`GET /key-store/<id>`](https://community.exoscale.com/reference/api/kms/key-store/#get-key-store)

Fetch an External Key Store including its latest XKS health observation when available.

Parameters:

  • parameters.id

Resources:

  • resources.key_store.id
  • resources.key_store.name
  • resources.key_store.description
  • resources.key_store.type
  • resources.key_store.status
  • resources.key_store.status_since
  • resources.key_store.created_at
  • resources.key_store.proxy.endpoint
  • resources.key_store.proxy.auth.key
  • resources.key_store.health.status
  • resources.key_store.health.status_reason
  • resources.key_store.health.checked_at
  • resources.key_store.health.error_detail
  • resources.key_store.health.metadata_json

connect-key-store

[`POST /key-store/<id>/connect`](https://community.exoscale.com/reference/api/kms/key-store/#connect-key-store)

Connects an External Key Store after validating the configured customer-managed XKS proxy, and resumes periodic proxy health checks.

Parameters:

  • parameters.id

Resources:

  • resources.key_store.id
  • resources.key_store.name
  • resources.key_store.description
  • resources.key_store.type
  • resources.key_store.status
  • resources.key_store.status_since
  • resources.key_store.created_at
  • resources.key_store.proxy.endpoint
  • resources.key_store.proxy.auth.key
  • resources.key_store.health.status
  • resources.key_store.health.status_reason
  • resources.key_store.health.checked_at
  • resources.key_store.health.error_detail
  • resources.key_store.health.metadata_json

disconnect-key-store

[`POST /key-store/<id>/disconnect`](https://community.exoscale.com/reference/api/kms/key-store/#disconnect-key-store)

Disconnects an External Key Store and suspends periodic proxy health checks.

Parameters:

  • parameters.id

Resources:

  • resources.key_store.id
  • resources.key_store.name
  • resources.key_store.description
  • resources.key_store.type
  • resources.key_store.status
  • resources.key_store.status_since
  • resources.key_store.created_at
  • resources.key_store.proxy.endpoint
  • resources.key_store.proxy.auth.key
  • resources.key_store.health.status
  • resources.key_store.health.status_reason
  • resources.key_store.health.checked_at
  • resources.key_store.health.error_detail
  • resources.key_store.health.metadata_json

delete-key-store

[`DELETE /key-store/<id>`](https://community.exoscale.com/reference/api/kms/key-store/#delete-key-store)

Deletes an External Key Store when no KMS keys reference it.

Parameters:

  • parameters.id

Resources:

  • resources.key_store.id
  • resources.key_store.name
  • resources.key_store.description
  • resources.key_store.type
  • resources.key_store.status
  • resources.key_store.status_since
  • resources.key_store.created_at
  • resources.key_store.proxy.endpoint
  • resources.key_store.proxy.auth.key
  • resources.key_store.health.status
  • resources.key_store.health.status_reason
  • resources.key_store.health.checked_at
  • resources.key_store.health.error_detail
  • resources.key_store.health.metadata_json
Last updated on