Hi Team,
Currently, we have KMS CMK configuration available on the project level.
We are hoping to see if that can be changed on cluster level.
Reason: Once we update the key, all the clusters will get re-encrypted with new key, but snapshots will not be re-encrypted with the new key.
For any reason, if we need to restore snapshot of one particular cluster, we will need to update KMS key with the old one, which impacts all clusters to get re-encrypted and then only can restore.
Hence we believe cluster level KMS setting would be beneficial in such a scenario where we wouldn't be impacting all clusters in a project.
Please feel free to reach out if you have any additional questions.
Thank you.
--Regards,
Srikanth Paruchuri.