<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CMK for managed services automatic rotation in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/cmk-for-managed-services-automatic-rotation/m-p/23896#M16578</link>
    <description>&lt;P&gt;Hi @Constantino Schillebeeckx​&amp;nbsp;, You can update/rotate CMK at a later time (on a running workspace). Please refer: &lt;A href="https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html?_ga=2.214562071.1895504292.1667411694-643525343.1663499643#add-or-update-a-customer-managed-key-on-a-running-workspace" alt="https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html?_ga=2.214562071.1895504292.1667411694-643525343.1663499643#add-or-update-a-customer-managed-key-on-a-running-workspace" target="_blank"&gt;https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html?_ga=2.214562071.1895504292.1667411694-643525343.1663499643#add-or-update-a-customer-managed-key-on-a-running-workspace&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Nov 2022 07:17:18 GMT</pubDate>
    <dc:creator>Debayan</dc:creator>
    <dc:date>2022-11-04T07:17:18Z</dc:date>
    <item>
      <title>CMK for managed services automatic rotation</title>
      <link>https://community.databricks.com/t5/data-engineering/cmk-for-managed-services-automatic-rotation/m-p/23895#M16577</link>
      <description>&lt;P&gt;The &lt;A href="https://docs.databricks.com/security/keys/customer-managed-keys-storage-aws.html#:~:text=After%20you%20add%20a%20customer%2Dmanaged%20key%20for,compatible%20with%20Databricks%20customer%2Dmanaged%20keys%20for%20storage." alt="https://docs.databricks.com/security/keys/customer-managed-keys-storage-aws.html#:~:text=After%20you%20add%20a%20customer%2Dmanaged%20key%20for,compatible%20with%20Databricks%20customer%2Dmanaged%20keys%20for%20storage." target="_blank"&gt;docs&lt;/A&gt; for the CMK for workspace storage states:&lt;/P&gt;&lt;P&gt;&lt;I&gt;After you add a customer-managed key for storage, you cannot later rotate the key by setting a different key ARN for the workspace. However, AWS provides&amp;nbsp;&lt;/I&gt;&lt;A href="https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html" alt="https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html" target="_blank"&gt;&lt;I&gt;automatic CMK master key rotation&lt;/I&gt;&lt;/A&gt;&lt;I&gt;, which rotates the underlying key without changing the key ARN&amp;nbsp;&lt;/I&gt;&lt;A href="https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html" alt="https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html" target="_blank"&gt;&lt;I&gt;as described in AWS docs&lt;/I&gt;&lt;/A&gt;&lt;I&gt;. Automatic CMK master key rotation is compatible with Databricks customer-managed keys for storage.&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However the &lt;A href="https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html" alt="https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html" target="_blank"&gt;docs for managed services&lt;/A&gt; does not make any mention automatic CMK master key rotation - does CMK for managed services support this AWS automation?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 16:39:02 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cmk-for-managed-services-automatic-rotation/m-p/23895#M16577</guid>
      <dc:creator>Constantino</dc:creator>
      <dc:date>2022-11-03T16:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: CMK for managed services automatic rotation</title>
      <link>https://community.databricks.com/t5/data-engineering/cmk-for-managed-services-automatic-rotation/m-p/23897#M16579</link>
      <description>&lt;P&gt;yep, I'm aware of manual key rotation, but I'd like to explicitly avoid it because:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html?_ga=2.214562071.1895504292.1667411694-643525343.1663499643#add-or-update-a-customer-managed-key-on-a-running-workspace:~:text=Terminate%20all%20running%20clusters%2C%20pools%2C%20and%20SQL%20warehouses." alt="https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html?_ga=2.214562071.1895504292.1667411694-643525343.1663499643#add-or-update-a-customer-managed-key-on-a-running-workspace:~:text=Terminate%20all%20running%20clusters%2C%20pools%2C%20and%20SQL%20warehouses." target="_blank"&gt;it requires we take down our clusters&lt;/A&gt; (not feasible for our reporting clusters)&lt;/LI&gt;&lt;LI&gt;it means we have to add extra infra to our terraform to execute the rotation (feels needless if AWS can already rotate them automatically)&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 04 Nov 2022 13:05:54 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cmk-for-managed-services-automatic-rotation/m-p/23897#M16579</guid>
      <dc:creator>Constantino</dc:creator>
      <dc:date>2022-11-04T13:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: CMK for managed services automatic rotation</title>
      <link>https://community.databricks.com/t5/data-engineering/cmk-for-managed-services-automatic-rotation/m-p/23896#M16578</link>
      <description>&lt;P&gt;Hi @Constantino Schillebeeckx​&amp;nbsp;, You can update/rotate CMK at a later time (on a running workspace). Please refer: &lt;A href="https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html?_ga=2.214562071.1895504292.1667411694-643525343.1663499643#add-or-update-a-customer-managed-key-on-a-running-workspace" alt="https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html?_ga=2.214562071.1895504292.1667411694-643525343.1663499643#add-or-update-a-customer-managed-key-on-a-running-workspace" target="_blank"&gt;https://docs.databricks.com/security/keys/customer-managed-keys-managed-services-aws.html?_ga=2.214562071.1895504292.1667411694-643525343.1663499643#add-or-update-a-customer-managed-key-on-a-running-workspace&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 07:17:18 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/cmk-for-managed-services-automatic-rotation/m-p/23896#M16578</guid>
      <dc:creator>Debayan</dc:creator>
      <dc:date>2022-11-04T07:17:18Z</dc:date>
    </item>
  </channel>
</rss>

