Disk Source Image Encryption Key Args
data class DiskSourceImageEncryptionKeyArgs(val kmsKeySelfLink: Output<String>? = null, val kmsKeyServiceAccount: Output<String>? = null, val rawKey: Output<String>? = null, val sha256: Output<String>? = null) : ConvertibleToJava<DiskSourceImageEncryptionKeyArgs>
Properties
Link copied to clipboard
The self link of the encryption key used to encrypt the disk. Also called KmsKeyName in the cloud console. Your project's Compute Engine System service account (service-{{PROJECT_NUMBER}}@compute-system.iam.gserviceaccount.com
) must have roles/cloudkms.cryptoKeyEncrypterDecrypter
to use this feature. See https://cloud.google.com/compute/docs/disks/customer-managed-encryption#encrypt_a_new_persistent_disk_with_your_own_keys
Link copied to clipboard
The service account used for the encryption request for the given KMS key. If absent, the Compute Engine Service Agent service account is used.