See below for the requirements to use BYOK with GCP.
GCP service account requirements
To use GCP with BYOK, create a new, unique service account user on the IAM & Admin > Service Account page.
Do not use an existing user account or existing access key.
Create an access key by logging in to GCP using the service account.
Do not use the access key more than one time.
Do not delete any access keys from the service account.
Do not attach the same GCP account to multiple Cryptographic Security Platform Vault clusters.
Do not share the GCP BYOK service account.
Assign the following roles to the GCP service account:
Required project-level roles:
roles/browser- one of
roles/cloudkms.adminorroles/cloudkms.viewerIf
roles/cloudkms.adminis not granted at the project level, you must add the service account as a principal withroles/cloudkms.adminaccess to any keyrings that you want to manage with this connection.
- For access-key rotation, configure one of the following permissions:
roles/iam.serviceAccountKeyAdmin: Grant this role at the project levelservice account: Add the service account as a principal withserviceAccountKeyAdminto the service account IAM policy as a binding.
Download the JSON file from the Key tab of the IAM & Admin > Service Account page. This JSON file will be your access key. For example:
{ "type": "service_account", "project_id": "my-project", "private_key_id": "1c2f3ca8f0aactj23cj653ca12c4abf09052j2ca", "private_key": "-----BEGIN PRIVATE KEY----- agbcjeiosaghklte23jbaNBgkqhkiG9w0BAQEFAASCBKkwggSAoIBAQDl1T/WCYd VbzFaiVqx8i/SHHKgVbEeyKfjkl123cji3lsjtjlk231VLcyXESGfaDWQprStxKu J2ItEO5sDrWVajVkMpiDHNKDrHBdlahxvvx2JJNhm5loteclqMub5i6KgXpP+J8T uGbZCDHqfCBIIPH123ro3MxOUWVzrpEysLSVPOXJIltRajbPF98B5bK5y3i4FB++ 0KgeRgwbVjfRpzxr/Xe6clm5YIwL7spDNlpaSO5yB/pJitrLxydTRB1qnHlSZ25u nBUThj6Z1xCPJ3gjk3sJK783placje45oH8rLEYokdpO0rtSUJzm8U2OS7BVd0Jd 6vHaCHhdAgMBAAECggEAA3mOXvG61qhLqdeQ5tM7DFJ0PuiOX7n/meZ9O46Vz7iD 4UhnAUQVeWZbOfH7PJG7JNEB5GFwX5EAHhhUAMZSnucXh/lwSMrjCuoPGBH5bfqS PWvkHqDG7Mrhw/49h6PaCaR/tEDFJJ+vbeAAfqCaVcCQr830HLQ/2WY4mE7Es7t1 yRNVfl81f3niea2CGYtM217UOUMM3tEE58+OL47ZOm7O8g1TWVtrs3tvQNqL06Pb Nv+N2SZRDUz2sTXpZtvzrQ3uKGmiW2jdasG50nbSR6Z/koCePWsyuHc3wTF2adLz +zrzHH7KfaCWuHL6HxqyCIt8huGcxECHYXkL3CjlsQKBgQDvD6fR6RRf8rshXCdT UQFTSMc0n4eaLiQfVXy9B5X9PzNrEM7HqAkceYJPQhD7wdO9jNJX19O6xY5puHbz GfpZPYqgLg4mbRLh6DgHgg/kLrWFgkESmSuP1ABISRY+wDWCCBfoO2VIsrhn155k BmiMigSKg6AiWavMGgu6Gbv+kQKBgQDrwnVNte3srXfugN3RsGtcSmQokngsKxXT OHQ4hmrDnXMtfZjfFVhZTDsbuz4vt80/9EiI/Jph/L+n4OFMZsbJUsAB7ig1YDho I3VSGL8PIbJ75c5BW5Aq0fWGqvh4QHXJIyWPy0pciZu8Ze4jrLQ+Ep+Rf3nVlUbw cDlJtY9bDQKBgQDABSI2gHJmM1FOFXhc+ucGn6Gqyi0gkclgBcmhCFPYzAggCqsd QgK3hX4+7YE4x1KtoUxfVLP0BLVEg++/ivFE9yK/UN76zIfrPxyqIzVigoY5jAt6 xd9wssfbSCF/G+Ke5KNXXUYYo71tY4sNKvyVTlMhc2KP1NkioxUiUYNokQKBgQDW PJUgEuysIE5Vu2DXBbvp1+gAPmlZqaVhlXF3VB58t/1MH0/lmJ36N52W66Xs8tdf AHtRkEoyNN1sjpvtM4/8rmew2VxMdK2NZHteKQKlm3d3wzKUjcIKR1UYFRFJJTpj lr6xVoiyYpHUt8OZQ31e0smSDAcIoWgfYbuNUaF9mQKBgQDof8RNDNYVAeMUnAr1 EkJoUrnu6dmApJajrm+QInxcR6QAXqBIvXjTkx+k+K+BMfXYW3J978Ux+uJW/ZXL Dh098jk7v4newIVuRrAOJKyTLVWROAg/VJC0IPVagI0JBwzyNuPlrcL4HcgwPWtv DefSTvCnsHGy1dYBGf0AZ6tRhg== -----END PRIVATE KEY-----", "client_email": "gcp-byok@my-project.iam.gserviceaccount.com", "client_id": "687456956321489204860", "auth_uri": "https://accounts.google.com/o/oauth2/auth", "token_uri": "https://oauth2.googlecerts.com/token", "auth_provider_x509_cert_url": "https://www.googlecerts.com/oauth2/v1/certs", "client_x509_cert_url": "https://www.googlecerts.com/robot/v3/metadata/x509/gcpbyok@my-project.iam.gserviceaccount.com", "universe_domain": "googlecerts.com"}GCP endpoint access requirements
If your organization restricts outbound access to the public internet, the following endpoints must be whitelisted for GCP BYOK to function correctly:
https://www.googleapis.com/auth/cloud-platformhttps://oauth2.googleapis.comhttps://cloudresourcemanager.googleapis.comhttps://iam.googleapis.comhttps://cloudkms.googleapis.comhttps://accounts.google.comIf a proxy is in use in the network, you can test these endpoints in the Vault application on the Settings > Proxy Settings Vault page.