EncryptionConfig describes the encryption config of a cluster that is encrypted with a CMEK (customer-managed encryption key).
The fully-qualified resource name of the KMS key. Each Cloud KMS key is regionalized and has the following format: projects/PROJECT/locations/REGION/keyRings/RING/cryptoKeys/KEY_NAME