12/2/2024 · Anshum Garg, Adhvik Kanagala
What this post added
This post details the implementation of Customer-Managed Encryption Keys (CMEK) and Role-Based Access Control (RBAC) with API key roles. For CMEK, it explains the architecture involving an encryption service that brokers access to customer-managed KMS keys, hierarchical encryption using KEKs and DEKs, and the key revocation process. For RBAC, it introduces six new roles, three for the control plane and three for the data plane, to enable more granular access control.