Key Vault creation in Azure - Time & Space Complexity
Start learning this pattern below
Jump into concepts and practice - no test required
When creating a Key Vault in Azure, it's important to understand how the time to complete the creation grows as you add more resources or configurations.
We want to know how the number of operations changes as we create more Key Vaults or add more settings.
Analyze the time complexity of the following operation sequence.
// Create a Key Vault with basic settings
az keyvault create \
--name MyKeyVault \
--resource-group MyResourceGroup \
--location eastus
// Add access policies
az keyvault set-policy \
--name MyKeyVault \
--object-id 00000000-0000-0000-0000-000000000000 \
--secret-permissions get list
This sequence creates one Key Vault and sets one access policy on it.
Identify the API calls, resource provisioning, data transfers that repeat.
- Primary operation: Creating a Key Vault resource (az keyvault create)
- Secondary operation: Setting access policies (az keyvault set-policy)
- How many times: Each Key Vault creation is one operation; each access policy added is one operation per policy.
As you create more Key Vaults, the number of create operations grows directly with the number of vaults.
Also, adding more access policies means more set-policy calls, growing with the number of policies.
| Input Size (n) | Approx. Api Calls/Operations |
|---|---|
| 10 Key Vaults, 1 policy each | 10 create + 10 set-policy = 20 |
| 100 Key Vaults, 5 policies each | 100 create + 500 set-policy = 600 |
| 1000 Key Vaults, 10 policies each | 1000 create + 10,000 set-policy = 11,000 |
Pattern observation: The total operations grow proportionally with the number of vaults and policies.
Time Complexity: O(n)
This means the time to create Key Vaults and set policies grows linearly with the number of vaults and policies.
[X] Wrong: "Creating multiple Key Vaults at once takes the same time as creating one."
[OK] Correct: Each Key Vault creation is a separate operation that takes time, so more vaults mean more total time.
Understanding how resource creation scales helps you design efficient cloud deployments and answer questions about automation and scaling in interviews.
"What if we batch multiple access policies in a single API call? How would the time complexity change?"
Practice
Solution
Step 1: Understand Azure Key Vault's role
Azure Key Vault is designed to securely store sensitive information like secrets, keys, and certificates.Step 2: Compare with other Azure services
Hosting VMs, managing subscriptions, and monitoring traffic are done by other Azure services, not Key Vault.Final Answer:
To securely store secrets, keys, and certificates -> Option CQuick Check:
Key Vault = Secure storage for secrets [OK]
- Confusing Key Vault with VM hosting
- Thinking Key Vault manages subscriptions
- Assuming Key Vault monitors network
myVault in the resource group myResourceGroup located in eastus?Solution
Step 1: Identify correct Azure CLI syntax
The correct command usesaz keyvault createwith parameters--name,--resource-group, and--location.Step 2: Check each option's parameters
az keyvault create --name myVault --resource-group myResourceGroup --location eastus matches the correct syntax exactly. Options B, C, and D use incorrect commands or parameter names.Final Answer:
az keyvault create --name myVault --resource-group myResourceGroup --location eastus -> Option AQuick Check:
Correct CLI syntax = az keyvault create --name myVault --resource-group myResourceGroup --location eastus [OK]
- Using 'az keyvault new' instead of 'create'
- Wrong parameter names like --vault or --group
- Omitting required parameters
az keyvault create --name testVault --resource-group testGroup --location westus --enable-soft-delete false
What will be the state of soft delete on the created Key Vault?
Solution
Step 1: Check parameter validity
The parameter--enable-soft-deleteis deprecated and cannot be set to false; soft delete is always enabled now.Step 2: Understand command behavior
Setting--enable-soft-delete falsecauses the command to fail because disabling soft delete is not allowed.Final Answer:
Command will fail due to invalid parameter -> Option DQuick Check:
Soft delete cannot be disabled now = Command will fail due to invalid parameter [OK]
- Assuming soft delete can be turned off
- Ignoring deprecation of --enable-soft-delete
- Thinking soft delete depends on region
az keyvault create --name vault123 --resource-group group123 --location eastus
But you get an error:
ResourceGroupNotFound. What is the most likely fix?Solution
Step 1: Understand the error
ResourceGroupNotFoundmeans the specified resource group does not exist.Step 2: Fix by creating the resource group
You must create the resource groupgroup123first usingaz group createbefore creating resources inside it.Final Answer:
Create the resource groupgroup123before creating the Key Vault -> Option BQuick Check:
Resource group must exist before Key Vault creation [OK]
- Trying to change location instead of creating group
- Changing vault name without checking group
- Adding unrelated parameters to fix error
- Name:
secureVault- Resource group:
prodGroup- Location:
centralus- Enable soft delete
- Set access policy to allow user with object ID
1234abcd to get and list secretsWhich Azure CLI command sequence correctly achieves this?
Solution
Step 1: Create Key Vault with default soft delete enabled
Soft delete is enabled by default and cannot be disabled, so no need to specify it.Step 2: Set access policy with correct syntax
Useaz keyvault set-policywith--object-idand--secret-permissions get listto allow the user to get and list secrets.Step 3: Verify command correctness
az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list uses correct commands and parameters. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get,list incorrectly uses comma between permissions. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete true --access-policy object-id=1234abcd permissions=secrets:get,list uses invalid parameters. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete false && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list tries to disable soft delete, which is invalid.Final Answer:
az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list -> Option AQuick Check:
Create then set-policy with correct permissions = az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list [OK]
- Trying to disable soft delete
- Using wrong parameter names for access policy
- Combining all settings in one invalid command
