After a key is disabled in the cloud and cannot be used by any applications, you can set the date for permanent key deletion.
To delete a CloudKey
- Log in to the Vault web GUI using an account with Cloud Admin privileges.
- In the top menu bar, click CloudKeys.
Click the CloudKeys tab.
Select the key set for the CloudKey that you want to delete. For Azure, you must also select the Type.
Select the CloudKey that you want to delete.
Click Actions > Delete CloudKey.
On the confirmation screen, enter the number of days when the CloudKey will be permanently deleted.
The maximum number of days is 30 for AWS, 90 for Azure, and 120 for GCP.
The minimum is 7 days or, on Azure, if Purge Protection is enabled.
- Click Delete.
You can cancel the deletion at any time before the CloudKey is permanently deleted.