# GCP Vertex AI vertex-featurestore Without CMEK

> Flags legacy Vertex AI featurestores with no customer-managed key, ahead of the service's 2027 sunset.

Source: https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vertex-featurestore-without-cmek

---

## A deprecated store holding production features

Featurestores are the resources of Vertex AI Feature Store (Legacy). Google's
[legacy Feature Store overview](https://cloud.google.com/vertex-ai/docs/featurestore/overview) says
the product is deprecated: from 17 May 2026 it gets only critical patches, and on
17 February 2027 it is fully sunset and its APIs stop working. Google points users to Feature Store
V2.

Yet legacy featurestores still hold feature values used to train and serve models, often including
customer attributes. The [Vertex AI CMEK list](https://cloud.google.com/vertex-ai/docs/general/cmek)
says a key on a featurestore covers the featurestore and all its content. Without one, that data
sits under Google default encryption.

## Listing featurestores and their keys

There is no gcloud surface for legacy featurestores, so use the REST API:

```bash
curl -H "Authorization: Bearer $(gcloud auth print-access-token)" \
  "https://REGION-aiplatform.googleapis.com/v1/projects/PROJECT_ID/locations/REGION/featurestores"
```

Check each result for an `encryptionSpec.kmsKeyName` value.

## When ZopNight raises it

ZopNight inventories each featurestore and records whether its encryption settings include a Cloud
KMS key. A confirmed absence raises the finding. Entity types, feature counts and online serving
nodes do not matter to this rule.

## What does not trigger it

A featurestore with a key is silent, as is one whose encryption settings were not collected.
Featurestores that nobody reads from are covered for cost by
<a href="https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-feature-store-idle">GCP Vertex AI Feature Store Idle</a>.

## Compliance signal, zero saving

There is no saving. With the sunset date fixed, the finding is best read as a prompt: if features
must be under your key, build that into the migration.

## Fixing it through the V2 migration

1. Create a Cloud KMS key in the region and grant the Vertex AI service agent the CryptoKey
   Encrypter/Decrypter role on it.
2. Create the V2 online store with that key; see the
   <a href="https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vertex-feature-online-store-without-cmek">feature online store page</a>
   for the Bigtable serving requirement.
3. Move feature data and serving clients to V2, then delete the legacy featurestore.

**Warning**
Google warns that if Vertex AI loses access to a featurestore's key for 30 days, it deletes every featurestore encrypted with it, and those names cannot be reused. Never disable a key that live stores depend on.
