Deploy DKE Service with DuoKey Cockpit
Deploy DKE Service with DuoKey Cockpit
Step-by-step guide to deploying a Double Key Encryption service
Prerequisites
- Access to DuoKey Cockpit (https://cockpit.duokey.cloud)
- A configured vault instance
- Azure tenant domain information
- Admin permissions in your organization
Deploy a DKE Service
From DuoKey Cockpit, open DKE 365 and click Deploy new service. The wizard has five steps.
Key Selection
Select the vault, then choose an RSA-2048 key from that vault to bind to the service — the Microsoft DKE client requires RSA-2048 and does not support RSA-4096. The Cockpit runs a preflight check (key validity, backend reachability, and a wrap/unwrap round-trip) before you continue.
Service Config
Set the service Name and Description, the wrap/unwrap Algorithm (RSA-OAEP-256), and the Cache Duration — how many hours the previous key keeps serving requests during a key rotation (default 24).
Azure AD
Select the identity provider used to auto-provision the Azure AD app registration when the service is enabled, then enter the Azure Tenant ID, Client ID and Audience.
Leaving the tenant ID empty keeps the service in a non-production, permissive mode — set it before going live.
Security
Optionally bind an existing access control policy from the dropdown — it defaults to No policy. You can also enable optional mTLS (client CA certificate, allowed subjects, header name) for an extra transport-level check on Decrypt calls.
Review & Deploy
Review the configuration summary and click Deploy to create the service.
A newly deployed service starts in the Provisioned state. Enabling it moves it to Running and, if no Azure AD app exists yet, auto-provisions one.
Service Lifecycle
| State | Description |
|---|---|
| Provisioned | Created but not yet active |
| Running | Active and serving DKE requests |
| Disabled | Temporarily turned off |
| Stopped | Torn down |
| Failed | Configuration or key error |
Only a service in the Running state serves GetKey / Decrypt requests.
Verify Deployment
Check Service Status
The service status should show as Running with a green indicator.
Test Service Accessibility
- Navigate to DKE 365 → find your service → open its details
- Copy the service URL shown there
Example DKE Service URL:
If the service launches successfully and displays a response, your DKE service is properly configured and ready to use.