Strengthening security and increasing control with CMEK and API key roles
12/2/2024
This post details the implementation of Customer-Managed Encryption Keys (CMEK) and Role-Based Access Control (RBAC) with API key roles. For CMEK, it explains the architecture involving an encryption service that brokers access to customer-managed KMS keys, hierarchical encryption using KEKs and DEKs, and the key revocation process. For RBAC, it introduces six new roles, three for the control plane and three for the data plane, to enable more granular access control.