Skip to content
Security sshkey

SSH key naming convention

The CAF abbreviation for SSH key is sshkey. Names can be 1 to 70 characters long and allow alphanumerics and hyphens. The name must be unique within the resource group.

Naming rules

CAF abbreviation sshkey
Length 1 to 70 characters
Allowed characters Alphanumerics (a-z, A-Z, 0-9), hyphens
Scope of uniqueness Unique within the resource group
CAF pattern sshkey-{workload}-{environment}-{region}-{instance}

Rules follow Microsoft's resource naming rules and CAF abbreviations. Some resource types have extra start/end character restrictions, so verify against the official docs before locking in a convention.

Naming Security resources

Key Vault has its own guide covering its strict 24 character global uniqueness and soft delete name reservation. Managed identities are cheap to create and usually provisioned per app or per function rather than shared, so unlike most of this list, their naming should tie tightly to the specific workload they are attached to.

VPN Gateway and Bastion resources are typically one per hub or region rather than one per environment, name them for the network boundary they protect. The common mistake is naming managed identities generically, id-prod for example, when dozens end up in the same subscription and it becomes impossible to tell which resource an identity actually belongs to.

Example names

Generated by the same engine as the name generator, so length and character rules are already applied.

Scenario Generated name Length
Payments API, production sshkey-payments-prod-eus-001 28/70
Web app, development sshkey-webapp-dev-weu-002 25/70
Analytics with company prefix sshkey-contoso-analytics-stage-uks-001 38/70

Naming in Terraform and Bicep

Build the name from variables so one module produces the right name in every environment.

Terraform
locals {
  ssh_key_name = "sshkey-${var.workload}-${var.environment}-${var.region}-001"
}
Bicep
var sshKeyName = 'sshkey-${workload}-${environment}-${region}-001'

Generate SSH key names for your workload

Free, no login. Validation and Terraform, Bicep, or CSV export included.

Open in the generator →

Related Security resources

See the full list of Azure resource naming rules or read the complete CAF naming guide.