Review Compute Engine disk encryption key management

Verify default encryption and configure key permissions and recovery when customer control is required.

Description

Compute Engine disks are encrypted at rest by default using Google-managed keys. The absence of a customer-managed or customer-supplied key does not mean plaintext storage, but the key control model must meet organizational requirements.

Cloud KMS customer-managed keys and directly supplied CSEKs have different management responsibilities. Loss of key access or a CSEK can make data unreadable; encryption does not replace disk access permissions.

Potential impact

  • The key control model may not meet ownership or audit requirements.
  • Key loss or incorrect permission changes can interrupt data access and service.

Remediation

Choose default encryption or customer-controlled keys according to the data requirements. For CSEK, supply a Base64-encoded, random 256-bit key through a protected input and keep it out of code and logs. Test key permissions, secure storage and recovery, and plan changes to existing disks through a supported data migration process.

Examples

These are disk creation excerpts. Replace the project and service account JSON file path with actual values. Supply disk_csek_base64 through a protected input containing a Base64-encoded random 32-byte key.

Before

yaml
- name: create a disk1
  google.cloud.gcp_compute_disk:
    name: test-disk1
    size_gb: 50
    zone: us-central1-a
    project: test_project
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present

- name: create a disk3
  google.cloud.gcp_compute_disk:
    name: test-disk3
    size_gb: 50
    disk_encryption_key:
      raw_key:
    zone: us-central1-a
    project: test_project
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present

The first task uses default encryption. The second task’s empty raw_key is not a valid CSEK and is not a way to disable encryption.

After

yaml
- name: create a disk
  google.cloud.gcp_compute_disk:
    name: test-disk
    size_gb: 50
    disk_encryption_key:
      raw_key: "{{ disk_csek_base64 }}"
    zone: us-central1-a
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
  no_log: true

This creates a new disk with an externally supplied CSEK and uses no_log to reduce exposure in task output. It does not replace the key on an existing disk; secure key storage remains necessary.

References