turbot/azure

steampipe plugin install azuresteampipe plugin install azure
On This Page
Get Involved

Table: azure_compute_disk_encryption_set

Disk Encryption Set simplifies the key management for managed disks. When a disk encryption set is created, a system-assigned managed identity is created in Azure Active Directory (AD) and associated with the disk encryption set.

Examples

Key vault associated with each disk encryption set

select
name,
split_part(active_key_source_vault_id, '/', 9) as vault_name,
split_part(active_key_url, '/', 5) as key_name
from
azure_compute_disk_encryption_set;

List of encryption sets which are not using customer managed key

select
name,
encryption_type
from
azure_compute_disk_encryption_set
where
(
encryption_type <> 'EncryptionAtRestWithPlatformAndCustomerKeys'
and encryption_type <> 'EncryptionAtRestWithCustomerKey'
);

Identity info of each disk encryption set

select
name,
identity_type,
identity_principal_id,
identity_tenant_id
from
azure_compute_disk_encryption_set;

.inspect azure_compute_disk_encryption_set

Azure Compute Disk Encryption Set

NameTypeDescription
active_key_source_vault_idtextResource id of the KeyVault containing the key or secret
active_key_urltextUrl pointing to a key or secret in KeyVault
akasjsonbArray of globally unique identifier strings (also known as) for the resource.
encryption_typetextContains the type of the encryption
idtextThe unique id identifying the resource in subscription
identity_principal_idtextThe object id of the Managed Identity Resource
identity_tenant_idtextThe tenant id of the Managed Identity Resource
identity_typetextThe type of Managed Identity used by the DiskEncryptionSet
nametextThe friendly name that identifies the disk encryption set
previous_keysjsonbA list of key vault keys previously used by this disk encryption set while a key rotation is in progress
provisioning_statetextThe disk encryption set provisioning state
regiontextThe Azure region/location in which the resource is located.
resource_grouptextThe resource group which holds this resource.
subscription_idtextThe Azure Subscription ID in which the resource is located.
tagsjsonbA map of tags for the resource.
titletextTitle of the resource.
typetextThe type of the resource in Azure