CustomerEncryptionKey

JSON representation
{
  "sha256": string,
  "kmsKeyServiceAccount": string,

  
  "rawKey": string,
  "rsaEncryptedKey": string,
  "kmsKeyName": string
  
}
Fields
sha256
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Output only. The RFC 4648 base64 encoded SHA-256 hash of the customer-supplied encryption key that protects this resource.

kmsKeyServiceAccount

string

The service account being used for the encryption request for the given KMS key. If absent, the Compute Engine default service account is used. For example:

"kmsKeyServiceAccount": "name@
projectId.iam.gserviceaccount.com/

Union field key.

key can be only one of the following:

rawKey
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Specifies a 256-bit customer-supplied encryption key, encoded in RFC 4648 base64 to either encrypt or decrypt this resource. You can provide either the

rawKey

or the

rsaEncryptedKey

. For example:

"rawKey":
"SGVsbG8gZnJvbSBHb29nbGUgQ2xvdWQgUGxhdGZvcm0="
rsaEncryptedKey
(deprecated)

string

Specifies an RFC 4648 base64 encoded, RSA-wrapped 2048-bit customer-supplied encryption key to either encrypt or decrypt this resource. You can provide either the

rawKey

or the

rsaEncryptedKey

. For example:

"rsaEncryptedKey":
"ieCx/NcW06PcT7Ep1X6LUTc/hLvUDYyzSZPPVCVPTVEohpeHASqC8uw5TzyO9U+Fka9JFH
z0mBibXUInrC/jEk014kCK/NPjYgEMOyssZ4ZINPKxlUh2zn1bV+MCaTICrdmuSBTWlUUiFoD
D6PYznLwh8ZNdaheCeZ8ewEXgFQ8V+sDroLaN3Xs3MDTXQEMMoNUXMCZEIpg9Vtp9x2oe=="

The key must meet the following requirements before you can provide it to Compute Engine:

  1. The key is wrapped using a Google Cloud-powered RSA public key certificate.
  2. After being wrapped, the key must be encoded in RFC 4648 base64 encoding.
Gets the Google Cloud-powered RSA public key certificate at:

https://cloud-certs.storage.googleapis.com/google-cloud-csek-ingress.pem
kmsKeyName

string

The name of the encryption key that is stored in Cloud de Confiance KMS. For example:

"kmsKeyName": "projects/
kms_project_id/locations/
region/keyRings/
key_region/cryptoKeys/key

The fully-qualifed key name may be returned for resource GET requests. For example:

"kmsKeyName": "projects/
kms_project_id/locations/
region/keyRings/
key_region/cryptoKeys/key
/cryptoKeyVersions/1