5.6.1 Use CMEK protected StorageClasses for GKE Persistent Disk volumes

Information

Use CMEK protected StorageClass objects for GKE Autopilot Persistent Disk volumes so newly provisioned Persistent Disks are encrypted with an approved Cloud KMS key. This applies to dynamically provisioned Persistent Disk volumes that use the Compute Engine Persistent Disk CSI driver and the disk-encryption-kms-key parameter.

Persistent Disks are encrypted at rest by default, but CMEK gives the organization direct control over the Cloud KMS key used to protect the disk encryption keys. This supports stronger key governance, including key access control, rotation, separation of duties, and the ability to disable key use when required by security or compliance processes.

Using a CMEK protected StorageClass helps ensure that new Persistent Disk volumes created by Kubernetes are encrypted consistently with approved key material. The disk-encryption-kms-key value must reference the fully qualified Cloud KMS key resource, and the key ring location must align with the cluster location requirements.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remediate any StorageClass or Persistent Disk that does not use an approved Cloud KMS key. CMEK for GKE Autopilot Persistent Disk volumes is applied through a CMEK protected StorageClass for new dynamically provisioned volumes. Existing Persistent Disks cannot be converted to CMEK in place, so noncompliant volumes must be replaced or migrated.

-

Grant the Compute Engine service agent for the cluster project roles/cloudkms.cryptoKeyEncrypterDecrypter on the approved Cloud KMS key.

-

Create a new CMEK protected StorageClass using the Persistent Disk CSI driver, pd.csi.storage.gke.io, and the approved disk-encryption-kms-key value.

-

Update new PersistentVolumeClaims to use the CMEK protected StorageClass . If this should be the default storage option, mark the CMEK protected StorageClass as the default only after validating the key, location, and access permissions.

-

For existing PersistentVolumes that do not return an approved diskEncryptionKey.kmsKeyName, provision a new CMEK protected Persistent Disk through the approved StorageClass, migrate the data, update the workload to use the new PersistentVolumeClaim, and retire the old volume after validation.

-

Rerun the audit commands and confirm that the StorageClass includes the approved disk-encryption-kms-key, the PersistentVolumes reference the expected StorageClass, and the underlying Compute Engine disks return the approved Cloud KMS key.

Impact:

CMEK protection applies to new Persistent Disks created through the CMEK enabled StorageClass, it does not retroactively change existing disks. The disk-encryption-kms-key parameter cannot be added to an existing StorageClass, so the StorageClass must be recreated or replaced if CMEK was not included. The Compute Engine service agent for the cluster project must have roles/cloudkms.cryptoKeyEncrypterDecrypter on the key, and CMEK protection cannot be removed from an existing Persistent Disk except by creating a new disk from a snapshot with different encryption settings.

See Also

https://workbench.cisecurity.org/benchmarks/24958

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|14.8

Plugin: GCP

Control ID: 498b9d8434c5b758015acd41b7c5212b620fa195d762d83aac5f563371e16414