[DOCS-13480] [Atlas] Fix inconsistency for Atlas & Cloud Provider KMS rotation alert in docs Created: 02/Mar/20  Updated: 29/Oct/23  Resolved: 12/Mar/20

Status: Closed
Project: Documentation
Component/s: Atlas
Affects Version/s: None
Fix Version/s: None

Type: Bug Priority: Major - P3
Reporter: Sigfrido Narvaez Assignee: Jonathan DeStefano
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified
Environment:

https://docs.atlas.mongodb.com/tutorial/security-aws-kms-rotate-key/


Participants:
Days since reply: 3 years, 48 weeks ago
Epic Link: DOCSP-6053
Story Points: 2

 Description   

Description

The documentation and default alerts for KMS rotation by Atlas are confusing.
(from what I understand) Atlas rotates the secondary keys (MongoDB Master Keys) every 90 days automatically and w/o prompting the Atlas Project administrator. An Alert is also enabled by default to prompt the administrator to rotate the Customer Master Key (CMK) every 90 days. This is the external key owned by our customers in their own KMS (AWS KMS, GCP Cloud KMS, Azure Keyvault) and not the secondary keys we create, aka MongoDB Master Keys. However the docs says it should be rotated every 365 days.

In summary, the Atlas alert is set to 90 days but the docs say 365 days.

https://docs.atlas.mongodb.com/tutorial/security-aws-kms-rotate-key/

Scope of changes

Impact to Other Docs

MVP (Work and Date)

Resources (Scope or Design Docs, Invision, etc.)



 Comments   
Comment by Jonathan DeStefano [ 12/Mar/20 ]

Updated:

Comment by Sigfrido Narvaez [ 11/Mar/20 ]

Otherwise LGTM

Comment by Sigfrido Narvaez [ 11/Mar/20 ]

jonathan.destefano looks correct but also noticed the documentation for AWS KMS is different than GCP KMS and Azure KeyVault? The docs say we create an alert for 90 days for AWS, but don't specify the days for Azure or Google.

Comment by Jonathan DeStefano [ 09/Mar/20 ]

Hi sigfrido.narvaez,

Mind taking a look at the PR above when you have some bandwidth? Thanks in advance.

Cheers,
Jon

Comment by Tahiya Chowdhury (Inactive) [ 05/Mar/20 ]

https://github.com/10gen/cloud-docs/pull/1415

Comment by Tahiya Chowdhury (Inactive) [ 05/Mar/20 ]

https://github.com/10gen/cloud-docs/pull/1415

Comment by Sigfrido Narvaez [ 02/Mar/20 ]

Slack thread: https://mongodb.slack.com/archives/C1QM2S60K/p1583128025302600?thread_ts=1579799912.025800&cid=C1QM2S60K

Generated at Thu Feb 08 08:07:54 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.