Vector Search index endpoints running without a customer-managed key
What does ZopNight detect here?
Vector Search index endpoints created without `encryptionSpec.kmsKeyName` rely on Google default encryption, and Google requires an Index and the IndexEndpoint serving it to be created with the same CMEK key. ZopNight flags index endpoints that have no key, as low-severity compliance findings, so a CMEK rollout can plan both halves together.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1342 |
| Category | compliance |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | no kmsKeyName in encryptionSpec |
| Source | ZopNight |
| Permissions used | aiplatform.indexEndpoints.list · aiplatform.indexEndpoints.get |
Where it applies
Why the index endpoint and its index must match
Vector Search splits serving into two resources: the index holds the vectors, the index endpoint serves queries against deployed indexes. Google’s Vertex AI CMEK reference says CMEK on either covers all data files used for Vector Search indexes stored in Cloud Storage, Pub/Sub and internal storage, and adds a hard rule: Index and IndexEndpoint must be created with the same key.
That makes an unkeyed index endpoint more than a single gap. You cannot serve a CMEK-protected index from it, so encrypting your embeddings under your own key means replacing the endpoint too. Embeddings are often derived from sensitive documents, which is why CMEK policies tend to reach them.
Listing index endpoints and their keys
gcloud ai index-endpoints list --region=REGION \ --format="table(name, displayName, encryptionSpec.kmsKeyName)"Blank in the key column means default encryption. Note the key on each index deployed to the endpoint as well, since they have to agree.
What ZopNight evaluates
For each index endpoint in the inventory, ZopNight records whether its encryption settings name a Cloud KMS key. A confirmed absence of a key raises the finding. Deployed indexes, query volume and network mode (public, VPC peering or Private Service Connect) do not affect it.
Where it raises nothing
Endpoints with a key are silent. When the encryption setting was not collected, no finding is produced. The index side is reported separately, by GCP Vertex AI vertex-index Without CMEK, and an endpoint serving nothing is a cost question for GCP Vertex AI Vector Search Endpoint Idle.
Compliance only
No saving is attached. The consequence of ignoring it is a CMEK policy that cannot be met for any index served from this endpoint.
Rebuilding the serving path under one key
-
Choose one key in the region, and grant the Vertex AI service agent (
service-PROJECT_NUMBER@gcp-sa-aiplatform.iam.gserviceaccount.com) the Cloud KMS CryptoKey Encrypter/Decrypter role on it. -
Create the endpoint with that key:
Terminal window gcloud ai index-endpoints create --region=REGION --display-name=NAME \--encryption-kms-key-name=KEY_RESOURCE_NAME -
Make sure each index you will deploy was created with the same key, then deploy it.
-
Move query clients to the new endpoint and delete the old one.