enabling-cmek-encryption

Enable CMEK encryption on CockroachDB Cloud clusters with AWS KMS, GCP Cloud KMS, or Azure Key Vault.

3|3|Updated Mar 11, 2026
One-click install
npx skills add https://github.com/cockroachdb/claude-plugin --skill enabling-cmek-encryption
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: enabling-cmek-encryption
Source: https://github.com/cockroachdb/claude-plugin/tree/main/skills/security-and-governance/enabling-cmek-encryption
Command: npx skills add https://github.com/cockroachdb/claude-plugin --skill enabling-cmek-encryption

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

CMEK enables organizations to manage data-at-rest encryption keys for CockroachDB Cloud clusters via their cloud provider's KMS, giving full control over key lifecycle and compliance.

Core Features & Use Cases

  • Enable CMEK on CockroachDB Cloud clusters with the Advanced plan and Advanced Security Add-on.
  • Create and manage KMS keys in AWS KMS, GCP Cloud KMS, or Azure Key Vault.
  • Verify CMEK configuration, rotate keys, and recover from key access issues.

Quick Start

Select your cloud KMS provider and apply the CMEK key spec to enable CMEK on your cluster.

Frequently Asked Questions about enabling-cmek-encryption

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enable CMEK encryption for CockroachDB Cloud?

To enable CMEK encryption, select your cloud KMS provider and apply the CMEK key spec to your CockroachDB Cloud cluster. This requires the Advanced plan with the Advanced Security Add-on.

What cloud KMS providers can I use for CockroachDB CMEK configuration?

CockroachDB Cloud CMEK configuration supports AWS KMS, GCP Cloud KMS, and Azure Key Vault. You can provision and manage your encryption keys through any of these providers.

Do I need the Advanced Security Add-on to manage CockroachDB encryption keys?

Yes, managing CockroachDB encryption keys via CMEK requires the Advanced plan and the Advanced Security Add-on. This ensures your environment meets the necessary eligibility requirements for data-at-rest encryption.

Can I rotate CMEK keys and verify configuration on CockroachDB Cloud?

Yes, you can verify CMEK configuration and rotate keys on CockroachDB Cloud. The process also covers recovery scenarios to help you regain access if key issues occur.

How does customer-managed encryption work for CockroachDB data at rest?

Customer-managed encryption allows organizations to manage data-at-rest encryption keys for CockroachDB Cloud clusters via their cloud provider's KMS, giving full control over key lifecycle and compliance.

What happens if there are key access issues during CMEK validation?

If key access issues occur during CMEK validation, rollback considerations and recovery scenarios are defined to help restore access. This ensures you can recover from key provisioning or access failures.