GCP Ubuntu 18.04环境下MongoDB静态数据加密:Google KMS可行性及实现
Absolutely! You can encrypt MongoDB's at-rest data using Google Cloud KMS (GCP KMS) on your Ubuntu 18.04 GCP instance. Let's walk through all the details, including answers to your KMIP question, prerequisites, and step-by-step setup.
Does Google Cloud KMS support KMIP?
Yes! Google Cloud KMS fully supports the Key Management Interoperability Protocol (KMIP)—the exact standard MongoDB Enterprise Edition uses to integrate with external key management systems for at-rest encryption. This native support makes the integration straightforward and reliable.
Prerequisites
Since you already have MongoDB Enterprise Edition installed, here's what else you'll need:
- A GCP account with permissions to manage KMS resources: Roles like
Cloud KMS Admin(to create key rings/keys) orCloud KMS CryptoKey Encrypter/Decrypter(to use existing keys) are required. - A GCP KMS key ring and symmetric crypto key (MongoDB relies on symmetric encryption for at-rest data).
- Outbound network access from your Ubuntu 18.04 instance to
cloudkms.googleapis.comon port 443 (this is allowed by default in most GCP VPCs, but double-check firewall rules if you hit issues). - Secure storage for client certificates/keys (used for KMIP authentication) that only the
mongodbsystem user can access.
Step-by-Step Setup
1. Create GCP KMS Resources
First, set up the key ring and crypto key in your GCP project. Use the gcloud CLI (install it on your Ubuntu instance if you haven't already) or the GCP Console:
Create a Key Ring
gcloud kms keyrings create mongodb-keyring --location us-central1
(Replace us-central1 with your preferred GCP region)
Create a Symmetric Crypto Key
gcloud kms keys create mongodb-encrypt-key --keyring mongodb-keyring --location us-central1 --purpose ENCRYPT_DECRYPT
- Add
--protection-level=HSMif you need hardware-backed key storage for enhanced security (default is software-level).
Register a KMIP Client Certificate
MongoDB uses mutual TLS to authenticate with GCP KMS via KMIP. Generate a client certificate and private key on your Ubuntu instance:
openssl req -x509 -newkey rsa:4096 -keyout mongodb-kms-client.key -out mongodb-kms-client.crt -days 365 -nodes -subj "/CN=mongodb-kms-client"
Register this certificate with your GCP KMS key ring:
gcloud kms kmip clients create mongodb-kms-client --keyring mongodb-keyring --location us-central1 --certificate-file mongodb-kms-client.crt
Move these files to a secure directory and restrict access:
sudo mkdir -p /etc/mongodb/kms sudo mv mongodb-kms-client.key mongodb-kms-client.crt /etc/mongodb/kms/ sudo chown -R mongodb:mongodb /etc/mongodb/kms sudo chmod 600 /etc/mongodb/kms/*
2. Configure MongoDB to Use GCP KMS
Edit your MongoDB configuration file (usually /etc/mongod.conf) to enable at-rest encryption with KMIP. Add or update the following section:
security: encryption: atRest: enabled: true kmip: keyIdentifier: "mongodb-encrypt-key" # Name of your GCP KMS crypto key serverName: "cloudkms.googleapis.com" port: 443 clientCertificateFile: "/etc/mongodb/kms/mongodb-kms-client.crt" clientPrivateKeyFile: "/etc/mongodb/kms/mongodb-kms-client.key" # Optional: Verify GCP's server certificate (pre-installed on Ubuntu 18.04) serverCAFile: "/etc/ssl/certs/GlobalSign_Root_CA.pem"
3. Restart MongoDB and Verify Encryption
Restart the mongod service to apply changes:
sudo systemctl restart mongod
Check logs to confirm successful KMS connection:
sudo tail -f /var/log/mongodb/mongod.log
Look for lines like KMIP client connected successfully to confirm the handshake worked.
To verify encryption is active, connect to the MongoDB shell and run:
use admin db.runCommand({getEncryptionState: 1})
You’ll see a response with atRestEncryptionEnabled: true and details about your KMIP configuration.
Key Notes
- Backup Critical Assets: Save copies of your client certificate, private key, and GCP KMS key materials. Losing these will lock you out of encrypted data.
- Cluster Compatibility: If using a replica set or sharded cluster, repeat configuration steps on all nodes.
- Permission Checks: Ensure the
mongodbuser has read access to KMS key files and your GCP service account holds the necessary KMS roles.
内容的提问来源于stack exchange,提问作者Salitha

