GoogleCloudPlatform / GoogleCloudPlatform/k8s-cloudkms-plugin

Looking for feedback on KMS v2 proposal

Open
#23 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
57
Forks
16
PR merge metrics
No merged PRs in 30d

Description

Hello 👋🏻

As part of Kubernetes 1.25 enhancement we (_sig-auth kms wg_) are proposing a new v2alpha1 `KeyManagementService` service contract to:
- enable fully automated key rotation for the latest key
- improve KMS plugin health check reliability
- improve observability of envelop operations between kube-apiserver, KMS plugins and KMS

This is the [doc](https://docs.google.com/document/d/1YHzSzITSS3ZNpf63E-rseDo-ocpxexp3ttzjBU2P8Ck/edit?usp=sharing) that documents the limitations with the current KMS v1 API.

In addition, we are also proposing a SIG-Auth maintained KMS plugin reference implementation. This implementation will support a key hierarchy design that implements the v2alpha1 API and will serve as a baseline that provides:
- improve readiness times for clusters with a large number of encrypted resources
- reduce the likelihood of hitting the external KMS request rate limit
- metrics and tracing support

We have a KEP open for this proposal that details the changes and design: https://github.com/kubernetes/enhancements/pull/3302

#### Call to action

We are looking for feedback on the proposed changes in the KEP from all the plugin authors who are currently using the KMS v1 API. Please review the proposal and comment on the PR if there are any questions/concerns with the proposed design.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.