From 01b2d40cb8f5588a1d0dd9c400bb698df0b3bf95 Mon Sep 17 00:00:00 2001 From: Graham Savage Date: Thu, 1 Oct 2026 16:50:13 +0100 Subject: [PATCH] docs: change the emphasis on customer-keys Within the Kosli Dedicated offering, we want to lower the importance of customer-supplied KMS keys. The availability of their Kosli instance will depend upon the availability of their keys - and if a user within their organisation revokes the grant, or deletes the keys, Kosli will be unable to recover the customer's data. This may well be what some customers want, but from talking to one or two customers, they aren't comfortable with carrying that risk -- they are paying us to be an available SaaS platform and don't want for our SLA to be impacted by their internal teams. Given that, we're now describing "dedicated keys" within our marketing material, indicating that Kosli will create keys specifically for Dedicated customers. If a customer really wants to manage their keys, they can do, and we'll support that with the documentation that remains on this site, however the bulletpoint indicating that a dedicated customer _must_ provide us with a KMS grant has been removed. This commit removes a link from the Dedicated Parameters page to the Customer Key page, and that's a good thing. Customers who want to use their own keys will see the menu item, and those that don't want it won't have to read a bulletpoint that makes it sound mandatory. --- administration/customer_kms_keys.md | 4 +++- administration/dedicated_instance_parameters.md | 1 - 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/administration/customer_kms_keys.md b/administration/customer_kms_keys.md index 54a2514..6c2cd83 100644 --- a/administration/customer_kms_keys.md +++ b/administration/customer_kms_keys.md @@ -4,7 +4,7 @@ description: "Create cross-account AWS KMS keys for Kosli Dedicated and share th icon: "key" --- -Kosli Dedicated is a single-tenant Kosli instance, hosted on infrastructure dedicated to your organization. On a Dedicated instance you provide Kosli with the AWS KMS keys that encrypt all data at rest. +Kosli Dedicated is a single-tenant Kosli instance, hosted on infrastructure dedicated to your organization. Kosli creates dedicated KMS keys to encrypt all data at rest, but some customers may wish to provide Kosli with their own AWS KMS keys. This page explains the process for doing this. Kosli hosts your data across two AWS regions — a **primary** and a **secondary** — so you provide a key in each region. This page walks through creating those keys in the AWS Console (with an equivalent [Terraform example](#terraform-example)) and sharing their ARNs with Kosli. @@ -21,6 +21,8 @@ A member of the Kosli Customer Success team will give you: - Permissions in that account to create and manage KMS keys. - The primary/secondary regions and the Kosli account ID (`<>`) from a member of the Kosli Customer Success team. +In addition, you should ensure that you have an in-house operational procedure to guarantee the availability of the keys; if the keys are destroyed, or the Kosli grant is revoked, Kosli's software will not be able to store new attestations or access existing data. Choosing to provide KMS keys to Kosli is a commitment to maintaining the availability of those keys. + ## Choose the key shape AWS does not permit **multi-region KMS keys** whose key material lives in a custom key store. diff --git a/administration/dedicated_instance_parameters.md b/administration/dedicated_instance_parameters.md index be08d9d..81cd012 100644 --- a/administration/dedicated_instance_parameters.md +++ b/administration/dedicated_instance_parameters.md @@ -15,7 +15,6 @@ A Kosli Dedicated instance is a single-tenant Kosli instance hosted on infrastru ### Hosting - **DNS host** — the hostname you want your instance to be reachable at (for example, `.kosli.com`). Kosli issues a TLS certificate for this hostname. -- **Customer KMS keys** — the ARNs of the AWS KMS keys that encrypt all data at rest. Follow [Customer KMS keys](/administration/customer_kms_keys) to create a primary key and a secondary-region replica (or two single-region keys) in your own AWS account and share the ARNs with Kosli. - **AWS regions** — the **primary** and **secondary** AWS regions your instance runs in. Both regions must be ones Kosli Dedicated supports; a member of the Kosli Customer Success team will confirm the current options. ### Network access