# GCP Vertex AI vertex-index Without CMEK

> Flags Vertex AI Vector Search indexes with no customer-managed key protecting their vector data files.

Source: https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vertex-index-without-cmek

---

## What sits inside an index

A Vector Search index is built from embeddings you supply, and embeddings are not anonymous: they
are computed from support tickets, contracts, code or medical notes, and can reveal a lot about the
source. According to [Google's CMEK documentation](https://cloud.google.com/vertex-ai/docs/general/cmek),
a key on an index protects all data files used for the index, whether in Cloud Storage, Pub/Sub or
internal storage.

A customer-managed key lets you rotate on your schedule, audit every use in Cloud KMS logs and
disable the key to make the data unreadable. Google default encryption offers none of those
levers.

## Checking indexes for a key

```bash
gcloud ai indexes list --region=REGION \
  --format="table(name, displayName, encryptionSpec.kmsKeyName)"
```

Any index with no value in the key column uses default encryption.

## The rule's single condition

ZopNight records, for every index it inventories, whether the index's encryption settings carry a
Cloud KMS key name. A confirmed "no key" fires the finding. Index size, update method (batch or
streaming) and whether it is deployed have no effect.

## When the index is not reported

Keyed indexes are silent. Missing encryption data leads to no finding rather than a guessed one.
An index that is not deployed anywhere is a separate cost signal, covered by
<a href="https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vector-search-index-not-deployed">GCP Vertex AI Vector Search Index Not Deployed</a>.

## No money involved

The saving is $0. The exposure is regulatory: embeddings of regulated data held without the key
control your policy requires.

## Rebuilding the index with a key

1. Create a Cloud KMS key in the index's region and grant the Vertex AI service agent the
   `roles/cloudkms.cryptoKeyEncrypterDecrypter` role on it.
2. Rebuild the index from its source files with the key:

   ```bash
   gcloud ai indexes create --region=REGION --display-name=NAME \
     --metadata-file=metadata.json \
     --encryption-kms-key-name=KEY_RESOURCE_NAME
   ```

3. Deploy it to an index endpoint that uses the same key; Google requires the two to match.
4. Switch queries over, undeploy and delete the old index.

**Note**
Keep the source embeddings in a CMEK-protected bucket too. The key on the index does not cover the Cloud Storage files you import from.
