Skip to main content
compliance · gcp

Legacy Vertex AI Feature Store featurestores without a customer-managed key

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Legacy Vertex AI featurestores created without an `encryption_spec` key hold every feature value under Google default encryption. ZopNight flags each such featurestore as a low-severity compliance finding; since Feature Store (Legacy) is deprecated and sunsets on 17 February 2027, the usual fix is migrating to Feature Store V2 with a key, not recreating the legacy store.

Signal and threshold

How ZopNight evaluates Legacy Vertex AI Feature Store featurestores without a customer-managed key.
Field Value
Rule IDsRC-1344
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdno kmsKeyName in encryptionSpec
SourceZopNight
Permissions usedaiplatform.featurestores.list · aiplatform.featurestores.get

A deprecated store holding production features

Featurestores are the resources of Vertex AI Feature Store (Legacy). Google’s legacy Feature Store overview says the product is deprecated: from 17 May 2026 it gets only critical patches, and on 17 February 2027 it is fully sunset and its APIs stop working. Google points users to Feature Store V2.

Yet legacy featurestores still hold feature values used to train and serve models, often including customer attributes. The Vertex AI CMEK list says a key on a featurestore covers the featurestore and all its content. Without one, that data sits under Google default encryption.

Listing featurestores and their keys

There is no gcloud surface for legacy featurestores, so use the REST API:

Terminal window
curl -H "Authorization: Bearer $(gcloud auth print-access-token)" \
"https://REGION-aiplatform.googleapis.com/v1/projects/PROJECT_ID/locations/REGION/featurestores"

Check each result for an encryptionSpec.kmsKeyName value.

When ZopNight raises it

ZopNight inventories each featurestore and records whether its encryption settings include a Cloud KMS key. A confirmed absence raises the finding. Entity types, feature counts and online serving nodes do not matter to this rule.

What does not trigger it

A featurestore with a key is silent, as is one whose encryption settings were not collected. Featurestores that nobody reads from are covered for cost by GCP Vertex AI Feature Store Idle.

Compliance signal, zero saving

There is no saving. With the sunset date fixed, the finding is best read as a prompt: if features must be under your key, build that into the migration.

Fixing it through the V2 migration

  1. Create a Cloud KMS key in the region and grant the Vertex AI service agent the CryptoKey Encrypter/Decrypter role on it.
  2. Create the V2 online store with that key; see the feature online store page for the Bigtable serving requirement.
  3. Move feature data and serving clients to V2, then delete the legacy featurestore.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·