Review separation of Cloud KMS administration and decryption

Separate key administrators from principals that decrypt data.

Description

Granting Cloud KMS administration and cryptographic-operation roles to the same principal weakens separation of duties between key management and data use. The administrator role does not itself grant decryption, but the effective combination of permissions, including IAM changes, needs review.

Potential impact

  • A compromised account could change key settings or permissions and decrypt ciphertext it can access.
  • Independent approval and auditing of changes can become harder.

Remediation

  • Assign key-management and cryptographic-operation roles to separate principals as required. Check whether group membership, inheritance or custom roles recombine those permissions.
  • Minimize access to keys and data, and review IAM changes and key-use records. After changing permissions, verify that required cryptographic operations still work.

Examples

google_project_iam_policy replaces the project’s entire IAM policy. Preserve other required bindings when using this excerpt to avoid losing administrative access. Replace the sample project and identities with actual values.

Before

hcl
resource "google_project_iam_policy" "project_policy" {
  project     = "your-project-id"
  policy_data = data.google_iam_policy.project_policy.policy_data
}

data "google_iam_policy" "project_policy" {
  binding {
    role = "roles/cloudkms.admin"

    members = [
      "user:jane@example.com",
    ]
  }

  binding {
    role = "roles/cloudkms.cryptoKeyDecrypter"

    members = [
      "user:jane@example.com",
    ]
  }
}

After

hcl
resource "google_project_iam_policy" "project_policy" {
  project     = "your-project-id"
  policy_data = data.google_iam_policy.project_policy.policy_data
}

data "google_iam_policy" "project_policy" {
  binding {
    role = "roles/cloudkms.admin"

    members = [
      "user:jane@example.com",
    ]
  }

  binding {
    role = "roles/cloudkms.cryptoKeyDecrypter"

    members = [
      "user:jane2@example.com",
    ]
  }
}

Explanation:

  • Before: One user receives both administration and decryption roles.
  • After: The roles are assigned to different users. Check remaining inherited permissions and other bindings separately.

References