Key Vault Managed HSM naming convention
The CAF abbreviation for Key Vault Managed HSM is kvmhsm.
Names can be 3 to 24 characters long and allow alphanumerics and hyphens.
The name must be globally unique across all of Azure.
Naming rules
| CAF abbreviation | kvmhsm |
|---|---|
| Length | 3 to 24 characters |
| Allowed characters | Alphanumerics (a-z, A-Z, 0-9), hyphens |
| Scope of uniqueness | Global (must be unique across all of Azure) |
| CAF pattern | kvmhsm-{workload}-{environment}-{region}-{instance} |
Rules follow Microsoft's resource naming rules and CAF abbreviations. Some resource types have extra start/end character restrictions, so verify against the official docs before locking in a convention.
Example names
Generated by the same engine as the name generator, so length and character rules are already applied.
| Scenario | Generated name | Length |
|---|---|---|
| Payments API, production | kvmhsm-payments-prod-001 Dropped region to fit the 24-char limit. | 24/24 |
| Web app, development | kvmhsm-webapp-dev-002 Dropped region to fit the 24-char limit. | 21/24 |
| Analytics with company prefix | kvmhsm-analyti-stage-001 Dropped company, region and shortened workload to fit 24 chars. | 24/24 |
Naming in Terraform and Bicep
Build the name from variables so one module produces the right name in every environment. The 24-character limit is enforced in the expression.
locals {
managed_hsm_name = substr("kvmhsm-${var.workload}-${var.environment}-${var.region}-001", 0, 24)
} var managedHsmName = take('kvmhsm-${workload}-${environment}-${region}-001', 24) Generate Key Vault Managed HSM names for your workload
Free, no login. Validation and Terraform, Bicep, or CSV export included.
Open in the generator →Related Security resources
See the full list of Azure resource naming rules or read the complete CAF naming guide.