Review encryption provider configuration

Check encryption provider order and key management to protect stored data.

Description

EncryptionConfiguration uses the first provider for a resource to write new data. If identity is first, new data for that resource is not encrypted even when encryption providers follow it.

The file’s contents matter more than its presence. Review both the selected providers and their order.

Potential impact

  • Sensitive resources such as Secrets may not receive the intended encryption.
  • A configuration file may appear protective without providing the expected protection.
  • Compliance with stored-data protection requirements may be assessed incorrectly.

Remediation

  • Put a suitable encryption provider first. Consider KMS v2 for external key management, and securely manage local-key access, rotation and recovery.
  • During migration, identity can follow the encryption provider to read existing plaintext. Meet each algorithm’s operational requirements, including automated key rotation for AES-GCM.
  • Coordinate decryption settings across API servers, safely rewrite existing resources and verify encryption. Do not first remove keys or providers needed to read existing data.

Examples

These examples compare provider order. The keys are public demonstration values: replace them with newly generated secure keys rather than reusing them in production. Separately restrict Secret API read permissions and access to the configuration file.

Before

yaml
apiVersion: apiserver.config.k8s.io/v1
kind: EncryptionConfiguration
resources:
  - resources:
      - secrets
    providers:
      - identity: {}
      - aesgcm:
          keys:
            - name: key1
              secret: c2VjcmV0IGlzIHNlY3VyZQ==

After

yaml
apiVersion: apiserver.config.k8s.io/v1
kind: EncryptionConfiguration
resources:
  - resources:
      - secrets
    providers:
      - secretbox:
          keys:
            - name: key1
              secret: YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXoxMjM0NTY=
      - identity: {}
      - aesgcm:
          keys:
            - name: key1
              secret: c2VjcmV0IGlzIHNlY3VyZQ==
      - aescbc:
          keys:
            - name: key1
              secret: c2VjcmV0IGlzIHNlY3VyZQ==

Explanation:

  • Before: identity is first, so new Secrets are not encrypted.
  • After: secretbox is first and encrypts new writes. Later providers can read existing data; existing resources are not automatically re-encrypted.

References