Skip to main content
compliance · gcp

Vector Search index endpoints running without a customer-managed key

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Vector Search index endpoints created without `encryptionSpec.kmsKeyName` rely on Google default encryption, and Google requires an Index and the IndexEndpoint serving it to be created with the same CMEK key. ZopNight flags index endpoints that have no key, as low-severity compliance findings, so a CMEK rollout can plan both halves together.

Signal and threshold

How ZopNight evaluates Vector Search index endpoints running without a customer-managed key.
Field Value
Rule IDsRC-1342
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdno kmsKeyName in encryptionSpec
SourceZopNight
Permissions usedaiplatform.indexEndpoints.list · aiplatform.indexEndpoints.get

Why the index endpoint and its index must match

Vector Search splits serving into two resources: the index holds the vectors, the index endpoint serves queries against deployed indexes. Google’s Vertex AI CMEK reference says CMEK on either covers all data files used for Vector Search indexes stored in Cloud Storage, Pub/Sub and internal storage, and adds a hard rule: Index and IndexEndpoint must be created with the same key.

That makes an unkeyed index endpoint more than a single gap. You cannot serve a CMEK-protected index from it, so encrypting your embeddings under your own key means replacing the endpoint too. Embeddings are often derived from sensitive documents, which is why CMEK policies tend to reach them.

Listing index endpoints and their keys

Terminal window
gcloud ai index-endpoints list --region=REGION \
--format="table(name, displayName, encryptionSpec.kmsKeyName)"

Blank in the key column means default encryption. Note the key on each index deployed to the endpoint as well, since they have to agree.

What ZopNight evaluates

For each index endpoint in the inventory, ZopNight records whether its encryption settings name a Cloud KMS key. A confirmed absence of a key raises the finding. Deployed indexes, query volume and network mode (public, VPC peering or Private Service Connect) do not affect it.

Where it raises nothing

Endpoints with a key are silent. When the encryption setting was not collected, no finding is produced. The index side is reported separately, by GCP Vertex AI vertex-index Without CMEK, and an endpoint serving nothing is a cost question for GCP Vertex AI Vector Search Endpoint Idle.

Compliance only

No saving is attached. The consequence of ignoring it is a CMEK policy that cannot be met for any index served from this endpoint.

Rebuilding the serving path under one key

  1. Choose one key in the region, and grant the Vertex AI service agent (service-PROJECT_NUMBER@gcp-sa-aiplatform.iam.gserviceaccount.com) the Cloud KMS CryptoKey Encrypter/Decrypter role on it.

  2. Create the endpoint with that key:

    Terminal window
    gcloud ai index-endpoints create --region=REGION --display-name=NAME \
    --encryption-kms-key-name=KEY_RESOURCE_NAME
  3. Make sure each index you will deploy was created with the same key, then deploy it.

  4. Move query clients to the new endpoint and delete the old one.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·