Component
Forge, Cast
Describe the feature you would like
Support signing with Azure Key Vault keys via a --azure wallet option, alongside --aws, --gcp and --turnkey.
Today an operator whose infrastructure is on Azure cannot keep a deployer key in their cloud KMS with Foundry: the options are a local keystore, a hardware wallet, or signing outside Foundry. Azure Key Vault and Managed HSM support secp256k1 (P-256K) keys with ES256K signing, so this is the same model as the AWS and GCP signers.
I have a proposed implementation and would like to open PRs if you are open to it. It depends on a new alloy-signer-azure crate, proposed in alloy-rs/alloy#4265.
foundry-wallets (foundry-core): foundry-rs/foundry-core@main...aelmanaa:foundry-core:feat/azure-key-vault-signer
- New
azure-key-vault feature, WalletSigner::Azure, and --azure in WalletOpts and MultiWalletOpts.
- The key is selected with
AZURE_KEY_VAULT_KEY_ID (e.g. https://<vault>.vault.azure.net/keys/<name>[/<version>]), or AZURE_KEY_VAULT_KEY_IDS (comma-separated) for forge script, mirroring AWS_KMS_KEY_ID(S).
- The Azure SDK for Rust has no default credential chain, so credentials are resolved in order from a service principal secret (
AZURE_CLIENT_SECRET), workload identity (AZURE_FEDERATED_TOKEN_FILE), the Azure CLI / Azure Developer CLI, and then a managed identity. The managed identity gets a 10s timeout because its endpoint can hang outside Azure and the SDK retries it for over a minute.
- Foundry: master...aelmanaa:foundry:feat/azure-key-vault-signer
- Feature passthrough in cast and forge, added to the release feature lists (Makefile, release and docker workflows),
cast wallet list --azure, the Tempo session and sponsor signer paths, and the --unlocked conflict.
- CLI tests for the feature-on and feature-off paths.
Both branches currently patch alloy and foundry-core from my forks; the patches would be replaced by releases before merging.
Open questions for maintainers:
- Naming:
--azure for the flag and azure-key-vault for the Cargo feature (Azure does not call Key Vault a "KMS", so azure-kms would match aws-kms / gcp-kms but be inaccurate). Happy to rename.
- The
AZURE_KEY_VAULT_KEY_IDS parsing is shared with AWS_KMS_KEY_IDS and now trims whitespace and ignores empty entries; I can drop that if you prefer to keep AWS untouched.
Additional context
I am running it end to end against a real Key Vault (Azure CLI login and service principal, cast send and forge script --broadcast on Sepolia) and will include the results in the PRs. The book pages for the new flag and env vars would follow in a separate PR to foundry-rs/book.
AI disclosure: the implementation was written primarily with Claude Code; I am reviewing and testing it before opening the PRs.
Component
Forge, Cast
Describe the feature you would like
Support signing with Azure Key Vault keys via a
--azurewallet option, alongside--aws,--gcpand--turnkey.Today an operator whose infrastructure is on Azure cannot keep a deployer key in their cloud KMS with Foundry: the options are a local keystore, a hardware wallet, or signing outside Foundry. Azure Key Vault and Managed HSM support secp256k1 (
P-256K) keys withES256Ksigning, so this is the same model as the AWS and GCP signers.I have a proposed implementation and would like to open PRs if you are open to it. It depends on a new
alloy-signer-azurecrate, proposed in alloy-rs/alloy#4265.foundry-wallets(foundry-core): foundry-rs/foundry-core@main...aelmanaa:foundry-core:feat/azure-key-vault-signerazure-key-vaultfeature,WalletSigner::Azure, and--azureinWalletOptsandMultiWalletOpts.AZURE_KEY_VAULT_KEY_ID(e.g.https://<vault>.vault.azure.net/keys/<name>[/<version>]), orAZURE_KEY_VAULT_KEY_IDS(comma-separated) forforge script, mirroringAWS_KMS_KEY_ID(S).AZURE_CLIENT_SECRET), workload identity (AZURE_FEDERATED_TOKEN_FILE), the Azure CLI / Azure Developer CLI, and then a managed identity. The managed identity gets a 10s timeout because its endpoint can hang outside Azure and the SDK retries it for over a minute.cast wallet list --azure, the Tempo session and sponsor signer paths, and the--unlockedconflict.Both branches currently patch alloy and foundry-core from my forks; the patches would be replaced by releases before merging.
Open questions for maintainers:
--azurefor the flag andazure-key-vaultfor the Cargo feature (Azure does not call Key Vault a "KMS", soazure-kmswould matchaws-kms/gcp-kmsbut be inaccurate). Happy to rename.AZURE_KEY_VAULT_KEY_IDSparsing is shared withAWS_KMS_KEY_IDSand now trims whitespace and ignores empty entries; I can drop that if you prefer to keep AWS untouched.Additional context
I am running it end to end against a real Key Vault (Azure CLI login and service principal,
cast sendandforge script --broadcaston Sepolia) and will include the results in the PRs. The book pages for the new flag and env vars would follow in a separate PR to foundry-rs/book.AI disclosure: the implementation was written primarily with Claude Code; I am reviewing and testing it before opening the PRs.