Skip to main content

Deploy DKE Service with DuoKey Cockpit

Applies to:
DuoKey CockpitDKE Web ServiceContainer Deployment

Prerequisites

  • Access to DuoKey Cockpit (https://cockpit.duokey.cloud)
  • A configured vault instance
  • Azure tenant domain information
  • Admin permissions in your organization

Deploy a DKE Service​

From DuoKey Cockpit, open DKE 365 and click Deploy new service. The wizard has five steps.

1

Key Selection

Select the vault, then choose an RSA-2048 key from that vault to bind to the service — the Microsoft DKE client requires RSA-2048 and does not support RSA-4096. The Cockpit runs a preflight check (key validity, backend reachability, and a wrap/unwrap round-trip) before you continue.

2

Service Config

Set the service Name and Description, the wrap/unwrap Algorithm (RSA-OAEP-256), and the Cache Duration — how many hours the previous key keeps serving requests during a key rotation (default 24).

3

Azure AD

Select the identity provider used to auto-provision the Azure AD app registration when the service is enabled, then enter the Azure Tenant ID, Client ID and Audience.

Tip

Leaving the tenant ID empty keeps the service in a non-production, permissive mode — set it before going live.

4

Security

Optionally bind an existing access control policy from the dropdown — it defaults to No policy. You can also enable optional mTLS (client CA certificate, allowed subjects, header name) for an extra transport-level check on Decrypt calls.

5

Review & Deploy

Review the configuration summary and click Deploy to create the service.

Note

A newly deployed service starts in the Provisioned state. Enabling it moves it to Running and, if no Azure AD app exists yet, auto-provisions one.

Service Lifecycle​

StateDescription
ProvisionedCreated but not yet active
RunningActive and serving DKE requests
DisabledTemporarily turned off
StoppedTorn down
FailedConfiguration or key error

Only a service in the Running state serves GetKey / Decrypt requests.

Verify Deployment​

Check Service Status​

The service status should show as Running with a green indicator.

Test Service Accessibility​

  1. Navigate to DKE 365 → find your service → open its details
  2. Copy the service URL shown there

Example DKE Service URL:

https://7d8550ae-e066-4d1b-b2b8-92581e5b0aef.duokey.cloud

Tip

If the service launches successfully and displays a response, your DKE service is properly configured and ready to use.

Troubleshooting​

What's Next​