NHN Cloud told public-sector customers Friday that every Kubernetes workload in its Government Zone must use customer-managed keys starting 3 November, eliminating the default option where NHN held data-encryption keys on platform hardware. The shift follows a Korea Internet & Security Agency spot audit that found three ministries could not produce complete rotation logs for secrets mounted in cluster namespaces.
What changes for tenants
Under the new policy, agencies must integrate Cloud Key Manager with their own hardware security modules or approved cloud HSM partitions before deploying production pods. NHN Cloud will reject cluster creation requests that rely on platform-managed keys for namespaces tagged gov-critical, a label already required for systems processing resident registration extracts.
Dev and staging clusters may keep platform keys until 31 March 2027, but traffic from those environments to production subnets will be blocked at the VPC edge—a move NHN Cloud engineers said prevents “key-hopping” mistakes seen in a Gyeonggi pilot last year.
Audit trigger
KISA’s August review sampled 14 ministries running containerized tax and welfare APIs. Four passed rotation tests; seven had partial logs; three could not demonstrate who approved key exports during contractor onboarding. NHN Cloud was not fined—the findings targeted tenant processes—but the cloud unit volunteered the CMK mandate to keep its Government Zone certification on schedule.
The Ministry of the Interior and Safety, which accredits government cloud regions, said it will embed CMK checks in quarterly conformity letters sent to agency CIOs. Failure to migrate by November triggers a written remediation plan, not an automatic shutdown, MOIS officials emphasized in a companion memo.
Implementation load
Agencies without existing HSM contracts must buy or lease modules through centralized procurement lists. NHN Cloud published Terraform modules and a 42-page migration workbook; early adopters at the Customs Service said they needed six weeks to re-encrypt persistent volumes without downtime, using dual-key reads during cutover.
Smaller municipalities on shared clusters worry about staffing. NHN Cloud is offering four free office hours sessions in Daejeon and Sejong through October, but will not operate customer keys on agencies’ behalf—a line drawn after a 2024 privacy ruling blamed shared custody for ambiguous breach notices.
Security rationale
Customer-managed keys mean NHN Cloud administrators cannot decrypt etcd backups without the agency’s HSM ceremony—even under court orders served on the vendor alone. That boundary matters for prosecutors’ requests involving welfare fraud datasets, where agencies have fought broad subpoenas.
Platform-managed keys were faster to deploy when Kubernetes adoption began in 2022. KISA now treats them as training wheels: acceptable for sandboxes, not for live citizen data at rest.
Open questions
It is unclear whether legacy VM instances in the same Government Zone must migrate simultaneously; NHN Cloud said a separate bulletin will cover block-storage keys in December. Whether non-Korean hyperscalers serving Korean agencies will mirror the CMK rule is outside NHN Cloud’s policy scope, MOIS noted.
Agencies that miss November deadlines may request one 60-day extension if they show HSM purchase orders—an escape valve Interior officials said prevents holiday-season outages on pension payment microservices.
Contractor onboarding
Three ministries blamed missing rotation logs on systems integrators who exported test keys to personal laptops during pandemic remote work. NHN Cloud’s workbook now requires integrators to use ephemeral keys that expire in 24 hours unless a named agency officer approves extension—a clause KISA said it will copy into broader cloud security guides.
Disaster recovery drills must prove agencies can rebuild clusters from CMK-backed backups without NHN operators in the room. A failed drill at one welfare ministry in July triggered this week’s policy acceleration, according to officials who attended the closed briefing.
Private-sector tenants on NHN’s commercial cloud are unaffected, but several chaebol affiliates said they may adopt CMK voluntarily after ransomware incidents elsewhere in Asia raised board-level questions about vendor-held keys.
NHN Cloud plans a November webinar walking agency security officers through HSM key ceremonies; attendance will count toward MOIS conformity letters for ministries still drafting migration timelines.








