Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion administration/customer_kms_keys.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: "Create cross-account AWS KMS keys for Kosli Dedicated and share th
icon: "key"
---

Kosli Dedicated is a single-tenant Kosli instance, hosted on infrastructure dedicated to your organization. On a Dedicated instance you provide Kosli with the AWS KMS keys that encrypt all data at rest.
Kosli Dedicated is a single-tenant Kosli instance, hosted on infrastructure dedicated to your organization. Kosli creates dedicated KMS keys to encrypt all data at rest, but some customers may wish to provide Kosli with their own AWS KMS keys. This page explains the process for doing this.

Kosli hosts your data across two AWS regions — a **primary** and a **secondary** — so you provide a key in each region. This page walks through creating those keys in the AWS Console (with an equivalent [Terraform example](#terraform-example)) and sharing their ARNs with Kosli.

Expand All @@ -21,6 +21,8 @@ A member of the Kosli Customer Success team will give you:
- Permissions in that account to create and manage KMS keys.
- The primary/secondary regions and the Kosli account ID (`<<kosli-account-id>>`) from a member of the Kosli Customer Success team.

In addition, you should ensure that you have an in-house operational procedure to guarantee the availability of the keys; if the keys are destroyed, or the Kosli grant is revoked, Kosli's software will not be able to store new attestations or access existing data. Choosing to provide KMS keys to Kosli is a commitment to maintaining the availability of those keys.
Comment thread
AlexKantor87 marked this conversation as resolved.

## Choose the key shape

AWS does not permit **multi-region KMS keys** whose key material lives in a custom key store.
Expand Down
1 change: 0 additions & 1 deletion administration/dedicated_instance_parameters.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,6 @@ A Kosli Dedicated instance is a single-tenant Kosli instance hosted on infrastru
### Hosting

- **DNS host** — the hostname you want your instance to be reachable at (for example, `<instance>.kosli.com`). Kosli issues a TLS certificate for this hostname.
- **Customer KMS keys** — the ARNs of the AWS KMS keys that encrypt all data at rest. Follow [Customer KMS keys](/administration/customer_kms_keys) to create a primary key and a secondary-region replica (or two single-region keys) in your own AWS account and share the ARNs with Kosli.
- **AWS regions** — the **primary** and **secondary** AWS regions your instance runs in. Both regions must be ones Kosli Dedicated supports; a member of the Kosli Customer Success team will confirm the current options.

### Network access
Expand Down
Loading