Yandex Cloud
Search
Contact UsGet started
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI for business
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
Terraform in Yandex Cloud
  • Getting started
  • Solution library
    • Overview
    • Release notes
          • kms_asymmetric_encryption_key
          • kms_asymmetric_encryption_key_iam_binding
          • kms_asymmetric_encryption_key_iam_member
          • kms_asymmetric_signature_key
          • kms_asymmetric_signature_key_iam_binding
          • kms_asymmetric_signature_key_iam_member
          • kms_secret_ciphertext
          • kms_symmetric_key
          • kms_symmetric_key_iam_binding
          • kms_symmetric_key_iam_member

In this article:

  • Example usage
  • Schema
  • Optional
  • Read-Only
  • Nested Schema for timeouts
  • Import
  1. Terraform reference
  2. Resources
  3. Key Management Service (KMS)
  4. Resources
  5. kms_asymmetric_signature_key

yandex_kms_asymmetric_signature_key (Resource)

Written by
Yandex Cloud
Updated at October 2, 2025
  • Example usage
  • Schema
    • Optional
    • Read-Only
    • Nested Schema for timeouts
  • Import

An asymmetric KMS key that may contain several versions of the cryptographic material.

Example usageExample usage

//
// Create a new KMS Assymetric Signature Key.
//
resource "yandex_kms_asymmetric_signature_key" "key-a" {
  name                = "example-asymetric-signature-key"
  description         = "description for key"
  signature_algorithm = "RSA_2048_SIGN_PSS_SHA_256"
}

SchemaSchema

OptionalOptional

  • asymmetric_signature_key_id (String) ID of the asymmetric KMS key to return.
    To get the ID of an asymmetric KMS key use a [AsymmetricSignatureKeyService.List] request.
  • deletion_protection (Boolean) Flag that inhibits deletion of the key
  • description (String) Description of the key.
  • folder_id (String) ID of the folder that the key belongs to.
  • id (String) ID of the asymmetric KMS key to return.
    To get the ID of an asymmetric KMS key use a [AsymmetricSignatureKeyService.List] request.
  • labels (Map of String) Custom labels for the key as key:value pairs. Maximum 64 per key.
  • name (String) Name of the key.
  • signature_algorithm (String) Signature Algorithm ID.
  • status (String) Current status of the key.
  • timeouts (Block, Optional) (see below for nested schema)

Read-OnlyRead-Only

  • created_at (String) Time when the key was created.

Nested Schema for Nested Schema for timeouts

Optional:

  • create (String) A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours).
  • delete (String) A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs.
  • read (String) A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled.
  • update (String) A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours).

ImportImport

The resource can be imported by using their resource ID. For getting the resource ID you can use Yandex Cloud Web Console or YC CLI.

# terraform import yandex_kms_asymmetric_signature_key.<resource Name> <resource Id>
terraform import yandex_kms_asymmetric_signature_key.key-a abjjf**********p3gp8

Was the article helpful?

Previous
kms_asymmetric_encryption_key_iam_member
Next
kms_asymmetric_signature_key_iam_binding
© 2025 Direct Cursus Technology L.L.C.