Skip to main content
compliance · gcp

Vertex AI Feature Store online stores created without a customer-managed key

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Vertex AI Feature Store online stores accept a customer-managed key only at creation, and only with Bigtable online serving; Optimized online serving has no CMEK option. ZopNight flags each `FeatureOnlineStore` with no Cloud KMS key as a low-severity compliance finding, since fixing it means a new Bigtable-served store.

Signal and threshold

How ZopNight evaluates Vertex AI Feature Store online stores created without a customer-managed key.
Field Value
Rule IDsRC-1345
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdno kmsKeyName in encryptionSpec
SourceZopNight
Permissions usedaiplatform.featureOnlineStores.list · aiplatform.featureOnlineStores.get

Serving type decides whether CMEK is possible

An online store is where Feature Store V2 serves feature values to models at request time. Google’s online store creation guide sets three constraints that shape this finding:

  • You specify the CMEK when you create the online store instance.
  • Only Bigtable online serving supports CMEK encryption.
  • The serving type, Bigtable or Optimized (now deprecated), cannot be changed after creation.

So an Optimized store can never be keyed, and a Bigtable store created without a key needs replacing. Google also notes CMEK can add usage cost depending on the key type, billed under Cloud KMS pricing.

Listing online stores

Terminal window
curl -H "Authorization: Bearer $(gcloud auth print-access-token)" \
"https://REGION-aiplatform.googleapis.com/v1/projects/PROJECT_ID/locations/REGION/featureOnlineStores"

For each store, look at encryptionSpec.kmsKeyName and note which serving type it was created with.

What ZopNight reads

ZopNight inventories each online store and records whether its encryption settings name a Cloud KMS key. When that record confirms no key, the finding is raised. Feature views, sync schedules and node counts are not part of the check, and the rule does not distinguish Optimized from Bigtable stores.

Stores the rule passes over

A store with a key is silent. If encryption data was not collected, nothing is raised. Online stores that serve little or nothing are a cost matter for GCP Vertex AI Feature Online Store Idle.

No saving; a small cost to fix

The finding reports no saving, and the fix may add Cloud KMS charges. It closes a key-control gap on data that models read in production.

Replacing the store with a keyed one

  1. Create a key in the store’s region and grant the Vertex AI service agent, service-PROJECT_NUMBER@gcp-sa-aiplatform.iam.gserviceaccount.com, the roles/cloudkms.cryptoKeyEncrypterDecrypter role.
  2. Create a new online store with Bigtable online serving and encryptionSpec.kmsKeyName set to the key.
  3. Recreate the feature views against the same BigQuery sources and let them sync.
  4. Point serving clients at the new store, then delete the old one.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·