Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Managed Service for Kubernetes
  • Comparing with other Yandex Cloud services
  • Getting started
    • Resource relationships
    • Release channels and updates
    • Support for Kubernetes versions
    • Zones of control in Managed Service for Kubernetes
    • Updating node group OS
    • Encryption
    • Networking in Managed Service for Kubernetes
    • Network settings and cluster policies
    • Autoscaling
    • Audit policy
    • External cluster nodes
    • Quotas and limits
    • Recommendations on using Managed Service for Kubernetes
    • Recommended master configurations
  • Access management
  • Pricing policy
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes

In this article:

  • Encryption with custom symmetric keys
  • Encrypting Kubernetes secrets
  • Use cases
  • Useful links
  1. Concepts
  2. Encryption

Encryption in Managed Service for Kubernetes

Written by
Yandex Cloud
Updated at July 13, 2026
View in Markdown
  • Encryption with custom symmetric keys
    • Encrypting Kubernetes secrets
  • Use cases
  • Useful links

Yandex Cloud adopts many information security measures. They include multi-level encryption of Managed Service for Kubernetes data:

  • Data is encrypted using system keys when it is transferred to a Yandex Cloud storage. This protects your data from being compromised in the event of a physical theft of disks from the Yandex Cloud data centers.
  • Data is encrypted when transmitted over the network using the TLS protocol. The keys for TLS are stored on hosts that use the protocol. This ensures protection of your data against interception.

The following cryptographic algorithms are used:

  • Symmetric: AES, ChaCha.
  • Asymmetric: RSA, Ed25519.

The minimum key length is 128 bits for symmetric encryption, and 2048 bits for asymmetric encryption.

Yandex Cloud manages these keys.

Encryption with custom symmetric keysEncryption with custom symmetric keys

Managed Service for Kubernetes supports encryption with custom Yandex Key Management Service symmetric keys for the following resources:

  • Kubernetes secrets
  • Disks for persistent volumes

Such keys are managed on the user side, which provides these extra advantages:

  • Auditing key-related events using Yandex Audit Trails.

  • Tracking operations with keys using Yandex Monitoring.

  • Operations with keys, such as rotation, modification, deactivation, and deletion.

  • Granular management of access permissions to the key at the level of individual Yandex Cloud accounts.

  • Using the hardware security module (HSM) when needed.

    Note

    In Managed Service for Kubernetes, a Yandex Cloud service account is called a cloud service account to avoid confusion with a Kubernetes service account.

Encrypting Kubernetes secretsEncrypting Kubernetes secrets

A Kubernetes secret is sensitive information the Kubernetes clusters use when managing pods, e.g., OAuth keys, passwords, SSH keys, etc.

By default, cluster secrets are stored unencrypted. If you specified an encryption key when creating a Managed Service for Kubernetes cluster, the cluster secrets will be encrypted.

Warning

You can specify an encryption key only when creating a cluster.

If you need to use another key, create a new cluster with that key.

The encryption of an individual secret includes these steps:

  1. Kubernetes encrypts the secret using the KMS provider.

  2. During encryption, the KMS provider accesses the KMS plugin that employs the encryption key you specified when creating the cluster.

    This key is not used to encrypt secrets directly. Instead, the envelope encryption algorithm involving the key is used.

    For a general description of the algorithm, see Envelope encryption.

  3. During encryption, the KMS plugin enables interaction with Yandex Key Management Service where the encryption key is stored.

    This plugin as well as the provider using it are already installed in the Managed Service for Kubernetes cluster and properly configured.

Secrets are decrypted in a similar way.

Use casesUse cases

  • Encrypting secrets in Managed Service for Kubernetes

  • Using encrypted disks for persistent volumes

  • Syncing with Yandex Lockbox secrets

Useful linksUseful links

  • Installing HashiCorp Vault with Key Management Service support
  • Using HashiCorp Vault to store secrets
  • Encrypting secrets in Managed Service for Kubernetes
  • Installing the External Secrets Operator with Yandex Lockbox support
  • Syncing with Yandex Lockbox secrets

Was the article helpful?

Previous
Updating node group OS
Next
Volume
© 2026 Direct Cursus Technology L.L.C.