# GCP Vertex AI vertex-index-endpoint Without CMEK

> Flags Vertex AI Vector Search index endpoints with no Cloud KMS key, which must share one key with their indexes.

Source: https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vertex-index-endpoint-without-cmek

---

## Why the index endpoint and its index must match

Vector Search splits serving into two resources: the index holds the vectors, the index endpoint
serves queries against deployed indexes. Google's
[Vertex AI CMEK reference](https://cloud.google.com/vertex-ai/docs/general/cmek) says CMEK on
either covers all data files used for Vector Search indexes stored in Cloud Storage, Pub/Sub and
internal storage, and adds a hard rule: Index and IndexEndpoint must be created with the same key.

That makes an unkeyed index endpoint more than a single gap. You cannot serve a CMEK-protected
index from it, so encrypting your embeddings under your own key means replacing the endpoint too.
Embeddings are often derived from sensitive documents, which is why CMEK policies tend to reach
them.

## Listing index endpoints and their keys

```bash
gcloud ai index-endpoints list --region=REGION \
  --format="table(name, displayName, encryptionSpec.kmsKeyName)"
```

Blank in the key column means default encryption. Note the key on each index deployed to the
endpoint as well, since they have to agree.

## What ZopNight evaluates

For each index endpoint in the inventory, ZopNight records whether its encryption settings name a
Cloud KMS key. A confirmed absence of a key raises the finding. Deployed indexes, query volume and
network mode (public, VPC peering or Private Service Connect) do not affect it.

## Where it raises nothing

Endpoints with a key are silent. When the encryption setting was not collected, no finding is
produced. The index side is reported separately, by
<a href="https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vertex-index-without-cmek">GCP Vertex AI vertex-index Without CMEK</a>,
and an endpoint serving nothing is a cost question for
<a href="https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vector-search-endpoint-idle">GCP Vertex AI Vector Search Endpoint Idle</a>.

## Compliance only

No saving is attached. The consequence of ignoring it is a CMEK policy that cannot be met for any
index served from this endpoint.

## Rebuilding the serving path under one key

1. Choose one key in the region, and grant the Vertex AI service agent
   (`service-PROJECT_NUMBER@gcp-sa-aiplatform.iam.gserviceaccount.com`) the Cloud KMS CryptoKey
   Encrypter/Decrypter role on it.
2. Create the endpoint with that key:

   ```bash
   gcloud ai index-endpoints create --region=REGION --display-name=NAME \
     --encryption-kms-key-name=KEY_RESOURCE_NAME
   ```

3. Make sure each index you will deploy was created with the same key, then deploy it.
4. Move query clients to the new endpoint and delete the old one.
