# GCP Vertex AI vertex-endpoint Without CMEK

> Flags Vertex AI endpoints that use Google default encryption instead of a Cloud KMS customer-managed key.

Source: https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vertex-endpoint-without-cmek

---

## What CMEK covers on a prediction endpoint

Every Vertex AI resource is encrypted at rest; the question is whose key. Google's
[CMEK page for Vertex AI](https://cloud.google.com/vertex-ai/docs/general/cmek), now published
under the Gemini Enterprise Agent Platform name, lists what a key protects on an endpoint: all
model files used for deployments under it, but not in-memory data. It also states the property
that makes CMEK worth having: if the key is disabled, the deployed model is automatically
undeployed. That is a kill switch you control from Cloud KMS, alongside key rotation schedules and
audit logs of key use.

With default encryption none of that exists. Google holds the key, and the only way to cut off the
endpoint is IAM or deletion.

## Checking which endpoints have a key

```bash
gcloud ai endpoints list --region=REGION \
  --format="table(name, displayName, encryptionSpec.kmsKeyName)"
```

An empty last column means the endpoint uses Google default encryption. Endpoints are regional, so
run it for each region you deploy in.

## How the finding is decided

When ZopNight inventories an endpoint it reads the endpoint's encryption settings and records
whether a Cloud KMS key name is present. The rule fires only on a confirmed "no key" record for a
resource of the endpoint type. It does not look at traffic, deployed models or cost.

## Endpoints that stay silent

An endpoint with any KMS key set passes, whatever key it is. If the encryption setting was not
collected for an endpoint, ZopNight does not assume the worst and raises nothing. Endpoints that
serve no traffic are a cost issue handled by
<a href="https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-endpoint-idle">GCP Vertex AI Endpoint Idle</a>.

## Key control, not savings

The finding carries no saving. The gap is control: no ability to rotate, disable or audit the key
protecting deployed model files, which regulated environments often require.

## Recreating the endpoint with a key

1. Create a key ring and key in the endpoint's region. The key must be in the same region as the
   resource.
2. Give the Vertex AI service agent,
   `service-PROJECT_NUMBER@gcp-sa-aiplatform.iam.gserviceaccount.com`, the
   `roles/cloudkms.cryptoKeyEncrypterDecrypter` role on the key with
   `gcloud kms keys add-iam-policy-binding`.
3. Create a replacement endpoint with the key:

   ```bash
   gcloud ai endpoints create --region=REGION --display-name=NAME \
     --encryption-kms-key-name=projects/P/locations/REGION/keyRings/KR/cryptoKeys/KEY
   ```

4. Deploy the model to the new endpoint, switch clients to its ID, then undeploy and delete the old
   one.

**Warning**
Deleting the old endpoint before clients move breaks predictions. Cut over first.
