diff --git a/administration/customer_kms_keys.md b/administration/customer_kms_keys.md index 54a2514..6c2cd83 100644 --- a/administration/customer_kms_keys.md +++ b/administration/customer_kms_keys.md @@ -4,7 +4,7 @@ description: "Create cross-account AWS KMS keys for Kosli Dedicated and share th icon: "key" --- -Kosli Dedicated is a single-tenant Kosli instance, hosted on infrastructure dedicated to your organization. On a Dedicated instance you provide Kosli with the AWS KMS keys that encrypt all data at rest. +Kosli Dedicated is a single-tenant Kosli instance, hosted on infrastructure dedicated to your organization. Kosli creates dedicated KMS keys to encrypt all data at rest, but some customers may wish to provide Kosli with their own AWS KMS keys. This page explains the process for doing this. Kosli hosts your data across two AWS regions — a **primary** and a **secondary** — so you provide a key in each region. This page walks through creating those keys in the AWS Console (with an equivalent [Terraform example](#terraform-example)) and sharing their ARNs with Kosli. @@ -21,6 +21,8 @@ A member of the Kosli Customer Success team will give you: - Permissions in that account to create and manage KMS keys. - The primary/secondary regions and the Kosli account ID (`<>`) from a member of the Kosli Customer Success team. +In addition, you should ensure that you have an in-house operational procedure to guarantee the availability of the keys; if the keys are destroyed, or the Kosli grant is revoked, Kosli's software will not be able to store new attestations or access existing data. Choosing to provide KMS keys to Kosli is a commitment to maintaining the availability of those keys. + ## Choose the key shape AWS does not permit **multi-region KMS keys** whose key material lives in a custom key store. diff --git a/administration/dedicated_instance_parameters.md b/administration/dedicated_instance_parameters.md index be08d9d..81cd012 100644 --- a/administration/dedicated_instance_parameters.md +++ b/administration/dedicated_instance_parameters.md @@ -15,7 +15,6 @@ A Kosli Dedicated instance is a single-tenant Kosli instance hosted on infrastru ### Hosting - **DNS host** — the hostname you want your instance to be reachable at (for example, `.kosli.com`). Kosli issues a TLS certificate for this hostname. -- **Customer KMS keys** — the ARNs of the AWS KMS keys that encrypt all data at rest. Follow [Customer KMS keys](/administration/customer_kms_keys) to create a primary key and a secondary-region replica (or two single-region keys) in your own AWS account and share the ARNs with Kosli. - **AWS regions** — the **primary** and **secondary** AWS regions your instance runs in. Both regions must be ones Kosli Dedicated supports; a member of the Kosli Customer Success team will confirm the current options. ### Network access