Create a vault and add a vault key
You can use your existing vault and vault key or create a new vault and vault key.
Regardless of which of the two options you choose, the vault and the vault key must
fulfill the following requirements:
- The key vault must have purge protection enabled and be located in the same subscription and region as the target Cloudera environment.
- The CMK must be an RSA key with a size of 2048 bits.
- The number of Disk Encryption Set (DES) resources is limited to 1000 per region per subscription. In the present implementation, a single DES is created for each Cloudera environment, so this permits at most 1000 environments created in that region/subscription. The actual practical limit may be lower due to the limits set for other resource types.
You should also review the Azure-imposed restrictions for CMKs used for disk encryption, described in Server-side encryption of Azure Disk Storage: Restrictions in the Azure documentation.
