Skip to content

feat: support Azure Key Vault signer (--azure) #17112

Description

@aelmanaa

Component

Forge, Cast

Describe the feature you would like

Support signing with Azure Key Vault keys via a --azure wallet option, alongside --aws, --gcp and --turnkey.

Today an operator whose infrastructure is on Azure cannot keep a deployer key in their cloud KMS with Foundry: the options are a local keystore, a hardware wallet, or signing outside Foundry. Azure Key Vault and Managed HSM support secp256k1 (P-256K) keys with ES256K signing, so this is the same model as the AWS and GCP signers.

I have a proposed implementation and would like to open PRs if you are open to it. It depends on a new alloy-signer-azure crate, proposed in alloy-rs/alloy#4265.

  • foundry-wallets (foundry-core): foundry-rs/foundry-core@main...aelmanaa:foundry-core:feat/azure-key-vault-signer
    • New azure-key-vault feature, WalletSigner::Azure, and --azure in WalletOpts and MultiWalletOpts.
    • The key is selected with AZURE_KEY_VAULT_KEY_ID (e.g. https://<vault>.vault.azure.net/keys/<name>[/<version>]), or AZURE_KEY_VAULT_KEY_IDS (comma-separated) for forge script, mirroring AWS_KMS_KEY_ID(S).
    • The Azure SDK for Rust has no default credential chain, so credentials are resolved in order from a service principal secret (AZURE_CLIENT_SECRET), workload identity (AZURE_FEDERATED_TOKEN_FILE), the Azure CLI / Azure Developer CLI, and then a managed identity. The managed identity gets a 10s timeout because its endpoint can hang outside Azure and the SDK retries it for over a minute.
  • Foundry: master...aelmanaa:foundry:feat/azure-key-vault-signer
    • Feature passthrough in cast and forge, added to the release feature lists (Makefile, release and docker workflows), cast wallet list --azure, the Tempo session and sponsor signer paths, and the --unlocked conflict.
    • CLI tests for the feature-on and feature-off paths.

Both branches currently patch alloy and foundry-core from my forks; the patches would be replaced by releases before merging.

Open questions for maintainers:

  • Naming: --azure for the flag and azure-key-vault for the Cargo feature (Azure does not call Key Vault a "KMS", so azure-kms would match aws-kms / gcp-kms but be inaccurate). Happy to rename.
  • The AZURE_KEY_VAULT_KEY_IDS parsing is shared with AWS_KMS_KEY_IDS and now trims whitespace and ignores empty entries; I can drop that if you prefer to keep AWS untouched.

Additional context

I am running it end to end against a real Key Vault (Azure CLI login and service principal, cast send and forge script --broadcast on Sepolia) and will include the results in the PRs. The book pages for the new flag and env vars would follow in a separate PR to foundry-rs/book.

AI disclosure: the implementation was written primarily with Claude Code; I am reviewing and testing it before opening the PRs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

  • Status
    Backlog

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions