Skip to main content

Getting Started

Applies to:
AWS KMSDuoKey CockpitXKS Proxy Setup

Overview​

Implementing DuoKey AWS XKS Proxy involves several key steps:

Implementation Steps

1
Choose Deployment ModelConnectivity option and key backend(s)
2
Prepare PrerequisitesAWS, DuoKey, and key manager components
3
Deploy the XKS EndpointConfigure the AWS XKS app in DuoKey Cockpit
4
Configure External Key StoreCreate and configure in AWS KMS
5
Create and Test KeysCreate KMS keys backed by external keys
6
Integrate with AWS ServicesBegin protecting your AWS resources

Deployment Decision Tree​

1. Connectivity Model​

OptionDescriptionBest For
Public InternetSimpler setup, lower operational overheadDevelopment/testing, robust internet security
Private Network/AWS VPCMore secure, traffic stays on AWS networkProduction, regulated workloads

2. Vault and Key Selection​

Each XKS endpoint is bound to a single AES-256 key in a single vault that you've already configured in DuoKey Cockpit — there is no per-request routing across multiple backends. If you need to expose more than one backend to AWS KMS, deploy a separate XKS endpoint for each.

Vault TypeBest For
HashiCorp VaultOrganizations already using Vault for secrets management
AWS KMSMulti-account AWS environments
DuoKey MPCDistributed threshold cryptography requirements

3. Compliance Requirements​

RequirementRecommendation
HIPAA, PCI DSS, FedRAMPUse VPC endpoint connectivity
Data SovereigntyConsider geographic placement of key manager
Audit RequirementsEnable comprehensive logging on all components

Prerequisites Checklist​

Prerequisites

  • AWS account with administrative access
  • AWS KMS enabled in target region(s)
  • IAM permissions for custom key stores and KMS keys
  • TLS certificates for proxy authentication
  • DuoKey Cockpit account and XKS Proxy license
  • A vault already configured in DuoKey Cockpit (e.g. HashiCorp Vault or DuoKey MPC) containing your AES-256 key
  • Network connectivity plan from AWS KMS to proxy
  • Round-trip time (RTT) under 35ms recommended

Quick Start: DuoKey Cockpit Wizard​

The easiest way to set up AWS XKS is through the DuoKey Cockpit wizard interface.

1

Access XKS Setup Wizard

Navigate to the DuoKey Cockpit and select the AWS XKS application setup wizard.

XKS Wizard Setup

Provide:

  • Application name for your XKS deployment
  • Basic configuration parameters
  • Connection endpoint details
2

Configure Access Control

Set up the access control and authentication settings for your XKS proxy.

XKS Access Control

Configure:

  • SigV4 authentication credentials
  • Access key ID and secret access key
  • Permission policies
3

Select Vault and Key

Choose the vault and AES-256 key this XKS endpoint will use. The vault must already be configured in DuoKey Cockpit.

Select Vault Backend

Example vault types:

  • HashiCorp Vault
  • AWS KMS
  • DuoKey MPC
4

Configure Secret Manager Store

Set up the connection to your chosen secret manager or key store.

Secret Manager Configuration

Provide:

  • Vault endpoint URL
  • Authentication credentials
  • Transit path or key storage location
  • Namespace (if applicable)
5

Review and Submit

Review all configuration settings before creating your XKS deployment.

Submit XKS Creation

Verify all connection parameters, authentication settings, backend configuration, and network settings.

6

Deploy the Application

Once submitted, the wizard will deploy your XKS proxy application.

Deploy XKS App

The system will create container instances, configure networking, set up health checks, and initialize connections to backends.

7

Verify Container Status

Wait for the container to be fully deployed and running.

Container XKS Running
8

Check Application Dashboard

Access the XKS application dashboard to monitor status and health.

XKS Dashboard
9

Download Configuration

Download the XKS JSON configuration file for AWS integration.

Download JSON Configuration

This file contains the XKS proxy endpoint URI, authentication credentials, and configuration parameters for AWS.

10

Configure AWS KMS

Upload the configuration to AWS or manually create the external key store.

Upload XKS Configuration

Deploying via the Management API (Alternative)​

The AWS XKS Proxy is a built-in feature of DuoKey Cockpit — there is nothing to download or install separately. If you prefer to automate deployment instead of using the wizard, call the JWT-authenticated management API directly.

Architecture Patterns​

Pattern 1: Single Backend (HashiCorp Vault)​

AWS KMS → Internet → DuoKey XKS Proxy → HashiCorp Vault

AttributeValue
Best ForOrganizations standardized on HashiCorp Vault
ComplexityLow

Pattern 2: Multiple Endpoints, Different Vaults​

AWS KMS → DuoKey Cockpit (XKS endpoint A → HashiCorp Vault)
AWS KMS → DuoKey Cockpit (XKS endpoint B → DuoKey MPC)

AttributeValue
Best ForOrganizations that need different keys backed by different vault types — each XKS endpoint is deployed separately and bound to one vault and key
ComplexityMedium

Pattern 3: High Availability with Load Balancing​

AWS KMS → Load Balancer (NLB/ALB) → XKS Proxy 1/2/3 → External Key Manager

AttributeValue
Best ForProduction environments requiring high availability
ComplexityHigh

Initial Configuration Checklist​

Pre-Key Creation Checklist

Proxy ConfigurationXKS endpoint deployed in DuoKey Cockpit, TLS configured, health check responding
AWS ConfigurationExternal key store created and connected, IAM policies attached
Backend ConfigurationExternal keys created, permissions configured, API access verified
Network ConfigurationFirewall rules configured, TLS handshake successful, RTT under 35ms
Security ConfigurationAccess controls implemented, audit logging enabled

Troubleshooting Initial Setup​

FAQ​

Next Steps​