# GCP Vertex AI vertex-feature-online-store Without CMEK

> Flags Vertex AI Feature Store online stores with no Cloud KMS key; only Bigtable serving supports one, set at creation.

Source: https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vertex-feature-online-store-without-cmek

---

## Serving type decides whether CMEK is possible

An online store is where Feature Store V2 serves feature values to models at request time. Google's
[online store creation guide](https://cloud.google.com/vertex-ai/docs/featurestore/latest/create-onlinestore)
sets three constraints that shape this finding:

- You specify the CMEK when you create the online store instance.
- Only Bigtable online serving supports CMEK encryption.
- The serving type, Bigtable or Optimized (now deprecated), cannot be changed after creation.

So an Optimized store can never be keyed, and a Bigtable store created without a key needs
replacing. Google also notes CMEK can add usage cost depending on the key type, billed under Cloud
KMS pricing.

## Listing online stores

```bash
curl -H "Authorization: Bearer $(gcloud auth print-access-token)" \
  "https://REGION-aiplatform.googleapis.com/v1/projects/PROJECT_ID/locations/REGION/featureOnlineStores"
```

For each store, look at `encryptionSpec.kmsKeyName` and note which serving type it was created
with.

## What ZopNight reads

ZopNight inventories each online store and records whether its encryption settings name a Cloud KMS
key. When that record confirms no key, the finding is raised. Feature views, sync schedules and
node counts are not part of the check, and the rule does not distinguish Optimized from Bigtable
stores.

## Stores the rule passes over

A store with a key is silent. If encryption data was not collected, nothing is raised. Online
stores that serve little or nothing are a cost matter for
<a href="https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-feature-online-store-idle">GCP Vertex AI Feature Online Store Idle</a>.

## No saving; a small cost to fix

The finding reports no saving, and the fix may add Cloud KMS charges. It closes a key-control gap
on data that models read in production.

## Replacing the store with a keyed one

1. Create a key in the store's region and grant the Vertex AI service agent,
   `service-PROJECT_NUMBER@gcp-sa-aiplatform.iam.gserviceaccount.com`, the
   `roles/cloudkms.cryptoKeyEncrypterDecrypter` role.
2. Create a new online store with Bigtable online serving and `encryptionSpec.kmsKeyName` set to
   the key.
3. Recreate the feature views against the same BigQuery sources and let them sync.
4. Point serving clients at the new store, then delete the old one.

**Warning**
Deleting the old store before the new feature views finish syncing leaves models with no features to read.
