Description
Compute Engine disks are encrypted at rest by default using Google-managed keys. The absence of a customer-managed or customer-supplied key does not mean plaintext storage, but the key control model must meet organizational requirements.
Cloud KMS customer-managed keys and directly supplied CSEKs have different management responsibilities. Loss of key access or a CSEK can make data unreadable; encryption does not replace disk access permissions.
Potential impact
- The key control model may not meet ownership or audit requirements.
- Key loss or incorrect permission changes can interrupt data access and service.
Remediation
Choose default encryption or customer-controlled keys according to the data requirements. For CSEK, supply a Base64-encoded, random 256-bit key through a protected input and keep it out of code and logs. Test key permissions, secure storage and recovery, and plan changes to existing disks through a supported data migration process.
Examples
These are disk creation excerpts. Replace the project and service account JSON file path with actual values. Supply disk_csek_base64 through a protected input containing a Base64-encoded random 32-byte key.
Before
- name: create a disk1
google.cloud.gcp_compute_disk:
name: test-disk1
size_gb: 50
zone: us-central1-a
project: test_project
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
- name: create a disk3
google.cloud.gcp_compute_disk:
name: test-disk3
size_gb: 50
disk_encryption_key:
raw_key:
zone: us-central1-a
project: test_project
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
The first task uses default encryption. The second task’s empty raw_key is not a valid CSEK and is not a way to disable encryption.
After
- name: create a disk
google.cloud.gcp_compute_disk:
name: test-disk
size_gb: 50
disk_encryption_key:
raw_key: "{{ disk_csek_base64 }}"
zone: us-central1-a
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
no_log: true
This creates a new disk with an externally supplied CSEK and uses no_log to reduce exposure in task output. It does not replace the key on an existing disk; secure key storage remains necessary.