Customer-managed encryption keys

By default, a Google-managed encryption key is used to encrypt disks and Cloud SQL instances in FreeIPA and Cloudera Data Hub clusters, but you can optionally configure Cloudera to use a customer-managed encryption key (CMEK) instead.

When a CMEK is provided during environment registration, that key encrypts all FreeIPA and Cloudera Data Hub disks and Cloud SQL instances.

Follow these steps to set up a CMEK.
  1. Review the CMEK requirements.
  2. Create a key ring and an encryption key.
  3. Assign the required permissions to the encryption key.

This document guides you through all the required steps performed using the GCP console and Google Cloud Shell. Once prerequisites are fulfilled, pass the encryption key when creating a Cloudera environment via the Cloudera web interface or Cloudera CLI.

For general information about customer-managed encryption keys, see Customer-managed encryption keys (CMEK).