Darshan Hiranandani : Evaluating the Security of Apigee X KVM Store for Storing Sensitive Data

Hi Team,

I’m Darshan Hiranandani, I’ve been using the KVM store in Apigee X to store sensitive credentials, but I’d like to ensure that the data is securely stored. I have a few questions regarding the security of the KVM store, and I’d appreciate your suggestions or insights:

  1. Are KVM maps encrypted by default when created via the management API, or is encryption only applied if specified during creation?

  2. How does Apigee X’s KVM Store compare to Secret Manager in terms of security when used within an Apigee proxy?

  3. Besides using a KVM policy, are there any other ways to access or read the values stored in KVM?

Looking forward to your feedback and suggestions!

Thanks!

Regards

Darshan Hiranandani

WTF https://www.googlecloudcommunity.com/gc/Apigee/How-secure-is-Apigee-X-KVM-store/m-p/695159