# Cluster with encryption at rest deleted - how to recover data

**URL:** <https://forums.percona.com/t/cluster-with-encryption-at-rest-deleted-how-to-recover-data/15742>\
**Category:** Percona Operator for MongoDB\
**Created:** [May 18, 2022, 4:54pm UTC](https://forums.percona.com/t/cluster-with-encryption-at-rest-deleted-how-to-recover-data/15742 "2022-05-18T16:54:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamoser](https://avatars.discourse-cdn.com/v4/letter/j/b2d939/32.png) [@jamoser](https://forums.percona.com/u/jamoser)\
**Post date:** [May 18, 2022, 4:54pm UTC](https://forums.percona.com/t/cluster-with-encryption-at-rest-deleted-how-to-recover-data/15742/1 "2022-05-18T16:54:48Z")

</div>

Hello

we just had a severe incident where our GKE cluster got deleted. Therefore any resources on it got deleted. Is there a way to recover the MongoDB data after all ? The disks are there but nothing else (even the encryption key is lost) …

1. How can I recover the encryption key ?
2. How can I recover mongodb-keyfile / mongodb-key ?
3. How can I bundle the disks so that they get accepted again as PVCs by the MongoDB cluster ?
4. Anything else to consider ?

Thanks  
John

PS: why are the critical keys generated ? If they would be part of the deployment, this would be preferable - so that they do not get forgotten to be backuped.

---

<div class="post-metadata">

**Author:** ![Sergey\_Pronin](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/sergey_pronin/32/14887_2.png) [@Sergey\_Pronin](https://forums.percona.com/u/Sergey_Pronin)\
**Post date:** [June 13, 2022, 8:25am UTC](https://forums.percona.com/t/cluster-with-encryption-at-rest-deleted-how-to-recover-data/15742/2 "2022-06-13T08:25:50Z")

</div>

We discussed it in private a bit.  
Summarizing it here:

- It is not possible to recover the cluster if the encryption key is lost. If it is possible, than we have a security flaw.
- Encryption key is generated by the Operator by default and stored in the Secret object: `my-cluster-name-mongodb-encryption-key`. User can always generate it manually and store it in another secret.
