Skip to content

docs: change the emphasis on customer-keys - #445

Merged
AlexKantor87 merged 1 commit into
mainfrom
dedicated-kms-keys
Oct 2, 2026
Merged

AlexKantor87 merged 1 commit into
mainfrom
dedicated-kms-keys

Conversation

@gsavage

@gsavage gsavage commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Within the Kosli Dedicated offering, we want to lower the importance of customer-supplied KMS keys. The availability of their Kosli instance will depend upon the availability of their keys - and if a user within their organisation revokes the grant, or deletes the keys, Kosli will be unable to recover the customer's data.

This may well be what some customers want, but from talking to one or two customers, they aren't comfortable with carrying that risk -- they are paying us to be an available SaaS platform and don't want for our SLA to be impacted by their internal teams.

Given that, we're now describing "dedicated keys" within our marketing material, indicating that Kosli will create keys specifically for Dedicated customers. If a customer really wants to manage their keys, they can do, and we'll support that with the documentation that remains on this site, however the bulletpoint indicating that a dedicated customer must provide us with a KMS grant has been removed.

This commit removes a link from the Dedicated Parameters page to the Customer Key page, and that's a good thing. Customers who want to use their own keys will see the menu item, and those that don't want it won't have to read a bulletpoint that makes it sound mandatory.

Within the Kosli Dedicated offering, we want to lower the importance of
customer-supplied KMS keys. The availability of their Kosli instance
will depend upon the availability of their keys - and if a user within
their organisation revokes the grant, or deletes the keys, Kosli will be
unable to recover the customer's data.

This may well be what some customers want, but from talking to one or
two customers, they aren't comfortable with carrying that risk -- they
are paying us to be an available SaaS platform and don't want for our
SLA to be impacted by their internal teams.

Given that, we're now describing "dedicated keys" within our marketing
material, indicating that Kosli will create keys specifically for
Dedicated customers.  If a customer really wants to manage their keys,
they can do, and we'll support that with the documentation that remains
on this site, however the bulletpoint indicating that a dedicated
customer _must_ provide us with a KMS grant has been removed.

This commit removes a link from the Dedicated Parameters page to the
Customer Key page, and that's a good thing. Customers who want to use
their own keys will see the menu item, and those that don't want it
won't have to read a bulletpoint that makes it sound mandatory.
@gsavage
gsavage requested a review from a team as a code owner October 1, 2026 16:49
@mintlify

mintlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
kosli 🟢 Ready View Preview Oct 1, 2026, 4:50 PM

@claude

claude Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @gsavage's task in 44s —— View job


I'll analyze this and get back to you.

Comment thread administration/customer_kms_keys.md
@claude

claude Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Doc review

No other page links to customer_kms_keys or mentions KMS keys, so nothing else on the site still says customer keys are required. The page keeps its entry in config/navigation.json.

administration/customer_kms_keys.md

  • Improvement — administration/customer_kms_keys.md:24: the availability and data-loss risk is a plain paragraph under Prerequisites. It also understates the impact: it says Kosli can't access the data, but the PR description says deleted keys mean Kosli can't recover it. Move it into a <Warning> right after the intro and say the loss is permanent. The inline comment has suggested wording.
  • Suggestion — administration/customer_kms_keys.md:3: the frontmatter description (used in search and link previews) still says the page is about creating keys "and share them with Kosli", with no sign that this is optional. Consider: "Optionally provide your own cross-account AWS KMS keys to encrypt Kosli Dedicated data at rest, instead of the dedicated keys Kosli creates."

administration/dedicated_instance_parameters.md

  • Suggestion — administration/dedicated_instance_parameters.md:15-18: removing the bullet is the right call. However, this page lists what Customer Success collects before deployment. A customer who wants their own keys will probably need to say so at that point, and the page now gives no hint that the option exists. If key choice is fixed at provisioning time, you could add an optional bullet such as: "Encryption keys (optional) — Kosli creates dedicated KMS keys for your instance by default. To supply your own instead, see Customer KMS keys." If keys can be switched after provisioning, ignore this.

1 Improvement, 2 Suggestions, nothing Critical. Fine to merge as is; the Improvement is worth doing first. This review is advisory.

View job run

@AlexKantor87
AlexKantor87 merged commit f9546a9 into main Oct 2, 2026
6 checks passed
@AlexKantor87
AlexKantor87 deleted the dedicated-kms-keys branch October 2, 2026 09:31

This branch was successfully deployed

1 active deployment
staging — 01b2d40c Deployed Oct 1, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants