Description
Compute Engine disks are encrypted at rest by default. Omitting a customer-supplied key (CSEK) or customer-managed key (CMEK) from diskEncryptionKey does not mean that data is stored in plaintext.
Critical VMs or regulated workloads may require separate control over key administration and use. Design customer key management when those requirements apply.
Potential impact
- Default key management may not meet organizational key-control or audit requirements.
- Losing a key or incorrectly restricting its use can interrupt disk access and recovery.
Remediation
- When customer keys are required, configure an actual
kmsKeyNameor securely storedrawKeyindiskEncryptionKey. Do not expose raw keys in public templates or logs. - Verify key location and the Compute Engine service agent's permissions, and establish recovery procedures. Plan key transitions for existing disks through supported copy or migration procedures.
Examples
These disk-setting excerpts use the retired Deployment Manager format. Supply omitted VM settings, including an image and zone, through a supported tool. Replace the sample KMS name with a real key in a compatible location and with the required permissions.
Before
yaml
resources:
- name: vm-template
type: compute.v1.instance
properties:
disks:
- boot: true
autoDelete: true
After
yaml
resources:
- name: vm-template
type: compute.v1.instance
properties:
disks:
- boot: true
autoDelete: true
diskEncryptionKey:
kmsKeyName: projects/sample/locations/global/keyRings/ring/cryptoKeys/key
Explanation:
- Before: No customer key is specified. This does not mean storage is unencrypted.
- After: A customer-managed KMS key is specified. Verify its actual association and the ability to use and recover the disk.