Review Secret encryption at rest in Tencent Cloud TKE

Check Secret encryption at rest and access to the KMS key in TKE.

Description

Tencent Cloud TKE KMS encryption protection encrypts Kubernetes Secrets stored in etcd. Where this protection is required but not enabled, a layer of defense against disclosure from storage exposure is missing.

This setting does not encrypt every volume or network connection. It also does not block users authorized to read Secrets, so restrict RBAC and key permissions separately.

Potential impact

  • Exposure of Secret storage can increase the risk of disclosing credentials, tokens and other secrets.
  • Missing required encryption at rest can leave organizational data-protection requirements unmet.

Remediation

Check the cluster’s actual encryption state. Where needed, configure tencentcloud_kubernetes_encryption_protection with the target cluster_id and kms_configuration. Select a supported cluster and the appropriate KMS key and region, and grant required service permissions. Do not disable or delete an active key; verify Secret operation and encryption status afterward.

Examples

These excerpts add an encryption-protection resource. The VPC data source is omitted. Match kms_region to the key’s actual region and configure required KMS permissions.

Before

hcl
resource "tencentcloud_kubernetes_cluster" "platform_cluster" {
  vpc_id                  = data.tencentcloud_vpc_subnets.vpc.instance_list.0.vpc_id
  cluster_cidr            = "10.32.0.0/16"
  cluster_max_pod_num     = 32
  cluster_name            = "tf_example_cluster"
  cluster_desc            = "example cluster"
  cluster_max_service_num = 32
  cluster_deploy_type     = "MANAGED_CLUSTER"
}

Only the cluster is defined; this excerpt includes no KMS encryption-protection configuration. Check the running cluster’s actual encryption state.

After

hcl
resource "tencentcloud_kubernetes_cluster" "platform_cluster" {
  vpc_id                  = data.tencentcloud_vpc_subnets.vpc.instance_list.0.vpc_id
  cluster_cidr            = "10.32.0.0/16"
  cluster_max_pod_num     = 32
  cluster_name            = "tf_example_cluster"
  cluster_desc            = "example cluster"
  cluster_max_service_num = 32
  cluster_deploy_type     = "MANAGED_CLUSTER"
}

resource "tencentcloud_kms_key" "cluster_key" {
  alias       = "tf-example-kms-key"
  description = "example of kms key instance"
  key_usage   = "ENCRYPT_DECRYPT"
  is_enabled  = true
}

resource "tencentcloud_kubernetes_encryption_protection" "cluster_encryption" {
  cluster_id = tencentcloud_kubernetes_cluster.platform_cluster.id

  kms_configuration {
    key_id     = tencentcloud_kms_key.cluster_key.id
    kms_region = "ap-guangzhou"
  }
}

This associates the cluster with a KMS key and encryption protection. Keep the key available and restrict Secret access separately.

References