Bring Your Own Key (BYOK) for Encryption at Rest
Encryption at rest in Elastic Cloud: Bring your own key with Google Cloud

Encryption at rest in Elastic Cloud: Bring your own key with Google Cloud

9/25/2024

What this post added

This post details the technical steps and considerations for integrating Elastic Cloud with Google Cloud KMS for Bring Your Own Key (BYOK) encryption at rest. It covers the architecture of the integration, prerequisites including Google Cloud IAM permissions and Elastic Enterprise license, the process of creating and configuring a Google Cloud KMS key, granting specific roles (Cloud KMS CryptoKey Encrypter/Decrypter, Cloud KMS Viewer) to Elastic service accounts, and completing the Elastic Cloud deployment creation with the Google Cloud Key resource name. It also outlines verification steps and discusses key rotation and revocation management within Google Cloud KMS and its impact on Elastic Cloud.

Read the original post ↗