Skip to content

Add idle Azure Managed HSM check #14

Description

@raphgm

Reserved for the SKILL.SCH open source community.\n\nAzure Managed HSM (Hardware Security Module) bills a fixed hourly rate (~$3.30/hr, real, current Retail Prices API) per pool regardless of key operation volume. A Managed HSM with zero real key vault operations over the lookback window is a significant, real recurring cost — this is one of the most expensive single always-on services in Azure, so even a single idle instance is a high-impact finding.\n\nNote: Managed HSM activation requires generating a security domain (multiple RSA key-pairs, a real multi-step process) before it's usable — this is more involved to provision for verification than most checks in this repo, so budget real time and read Microsoft's activation docs first.

Activity

  1. raphgm commented on Sep 22, 2026

    @raphgm
    OwnerAuthor

    Resolved in commit db56fa3. Note: an earlier PR (#24) attempted this but merged a non-functional, fabricated version — SQL policy + tests only, no source/extraction file, no runner.py registration, and a flat $10.00 price (real price is $3.20/hour = $2,336/month, off by ~233x — the Retail Prices API has no queryable meter for this product, so the real price came from Microsoft's own published Key Vault pricing page). That version was replaced with a real implementation. Also caught a second real bug during verification: the source read the wrong SKU field name, silently returning a $0 price until fixed. Verified against a real Standard_B1 HSM with 0 real key operations -> $2,336/month flagged correctly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedExtra attention is needed

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions