Review Compute Engine disk encryption key management

Distinguish default storage encryption from customer key control and apply the required key policy.

Description

Compute Engine disks are encrypted at rest by default. Omitting a customer-supplied key (CSEK) or customer-managed key (CMEK) from diskEncryptionKey does not mean that data is stored in plaintext.

Critical VMs or regulated workloads may require separate control over key administration and use. Design customer key management when those requirements apply.

Potential impact

  • Default key management may not meet organizational key-control or audit requirements.
  • Losing a key or incorrectly restricting its use can interrupt disk access and recovery.

Remediation

  • When customer keys are required, configure an actual kmsKeyName or securely stored rawKey in diskEncryptionKey. Do not expose raw keys in public templates or logs.
  • Verify key location and the Compute Engine service agent's permissions, and establish recovery procedures. Plan key transitions for existing disks through supported copy or migration procedures.

Examples

These disk-setting excerpts use the retired Deployment Manager format. Supply omitted VM settings, including an image and zone, through a supported tool. Replace the sample KMS name with a real key in a compatible location and with the required permissions.

Before

yaml
resources:
  - name: vm-template
    type: compute.v1.instance
    properties:
      disks:
        - boot: true
          autoDelete: true

After

yaml
resources:
  - name: vm-template
    type: compute.v1.instance
    properties:
      disks:
        - boot: true
          autoDelete: true
          diskEncryptionKey:
            kmsKeyName: projects/sample/locations/global/keyRings/ring/cryptoKeys/key

Explanation:

  • Before: No customer key is specified. This does not mean storage is unencrypted.
  • After: A customer-managed KMS key is specified. Verify its actual association and the ability to use and recover the disk.

References