Vector Search indexes built without a customer-managed encryption key
What does ZopNight detect here?
Vector Search indexes created without `--encryption-kms-key-name` keep their vector data files in Cloud Storage, Pub/Sub and internal storage under Google default encryption. ZopNight flags each index lacking a Cloud KMS key, as a low-severity compliance finding, since embeddings derived from private documents usually fall under the same CMEK policy as the documents.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1343 |
| Category | compliance |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | no kmsKeyName in encryptionSpec |
| Source | ZopNight |
| Permissions used | aiplatform.indexes.list · aiplatform.indexes.get |
Where it applies
What sits inside an index
A Vector Search index is built from embeddings you supply, and embeddings are not anonymous: they are computed from support tickets, contracts, code or medical notes, and can reveal a lot about the source. According to Google’s CMEK documentation, a key on an index protects all data files used for the index, whether in Cloud Storage, Pub/Sub or internal storage.
A customer-managed key lets you rotate on your schedule, audit every use in Cloud KMS logs and disable the key to make the data unreadable. Google default encryption offers none of those levers.
Checking indexes for a key
gcloud ai indexes list --region=REGION \ --format="table(name, displayName, encryptionSpec.kmsKeyName)"Any index with no value in the key column uses default encryption.
The rule’s single condition
ZopNight records, for every index it inventories, whether the index’s encryption settings carry a Cloud KMS key name. A confirmed “no key” fires the finding. Index size, update method (batch or streaming) and whether it is deployed have no effect.
When the index is not reported
Keyed indexes are silent. Missing encryption data leads to no finding rather than a guessed one. An index that is not deployed anywhere is a separate cost signal, covered by GCP Vertex AI Vector Search Index Not Deployed.
No money involved
The saving is $0. The exposure is regulatory: embeddings of regulated data held without the key control your policy requires.
Rebuilding the index with a key
-
Create a Cloud KMS key in the index’s region and grant the Vertex AI service agent the
roles/cloudkms.cryptoKeyEncrypterDecrypterrole on it. -
Rebuild the index from its source files with the key:
Terminal window gcloud ai indexes create --region=REGION --display-name=NAME \--metadata-file=metadata.json \--encryption-kms-key-name=KEY_RESOURCE_NAME -
Deploy it to an index endpoint that uses the same key; Google requires the two to match.
-
Switch queries over, undeploy and delete the old index.