Skip to content

Relationships

Schema relationships
graph LR
    ManagedKeys -->|"account"| Accounts

Properties

idstring
required·

Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.

accountstring

The account, subscription or project this object belongs to.

References: Accounts → id
alias_namesstring[]

Human-readable aliases for the key.

collected_atstring · date-time

When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.

container_protection_settingsobject

Settings on the vault or key ring that prevent accidental deletion — purge protection, soft delete, deletion prevention.

created_atstring

When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.

deletion_window_daysinteger

How long the provider waits before destroying a key scheduled for deletion.

key_idstring

The provider's own identifier for the key.

key_policy_documentstring

The raw key policy document, where it could be read.

key_specstring

The provider's own key specification string, verbatim.

key_typestring

The key's cryptographic type, as the provider names it.

managed_bystring

Who manages the key: the provider, the customer, or an external key store.

Possible values:
providercustomerexternalunknown
multi_regionboolean

Whether this key is part of a multi-region key set. Rotation is a shared property configured only on the primary key in the set.

native_typestring

The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.

next_rotation_atstring · date-time

When the key is next due to rotate.

originstring

Where the key material came from — generated in the key service, imported, or held in an external or hardware key store.

policy_grants_anyoneboolean

Whether the key policy grants use to anyone. A heuristic (absence of a scoping condition on a wildcard principal), not a provider fact. Doesn't account for grants, a separate authorization path, and cross-account policy reads are commonly permission_denied.

policy_scoping_conditionsstring[]

The condition keys found scoping the key policy's wildcard principal, if any.

protection_levelstring

Whether key material is held in software or in a hardware security module.

providerstring

Which cloud this object was read from.

Possible values:
awsazuregcp
provider_idstring

The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.

regionstring

Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.

remote_dataRecord<string, any>

Raw data returned from the remote API call.

rotation_applicableboolean

Whether rotation is a meaningful question for this key type, so a null rotation_enabled isn't mistaken for missing data.

rotation_enabledboolean

Whether automatic rotation is on. Null (not false) when rotation doesn't apply to the key type at all — e.g. asymmetric, HMAC, and custom-key-store keys.

rotation_period_daysinteger

How often the key rotates, in days. A key with no rotation period never rotates — distinct from a missing field, which unreadable_fields declares with not_configured.

scheduled_destroy_atstring · date-time

When the key is scheduled for destruction, where deletion is pending.

statestring

The provider's own key state string, verbatim.

tagsobject

Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.

unreadable_fieldsobject[]

Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.

detailstring

Explanation of the reason, where one adds anything.

fieldstring

The property on this resource that could not be read.

reasonstring

Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.

Possible values:
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
updated_atstring

When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.