Before you can use CSP Vault as a GCP EKM provider, you must set up the following parameters on the Cloud Service Provider Account details page.

EKM URI

The EKM URI is the URI GCP uses to access keys from the CSP Vault.

  • If you deploy a single CSP Vault, set the  EKM URI  directly to that vault. 
  • If you deploy a cluster with multiple nodes, set the EKM URI to the load balancer.

For EKM via Internet, use the following format:

https://example.server.com

For EKM via VPC, use the following format:  

https://<hostname>

Key Access Justification Policy

We highly recommend creating a Key Access Justification policy at the Cloud Service Provider and KeySet level that specifies access justification reasons. These apply to all the keys created in this KeySet, unless the policy is specified at the key level, which overrides this policy.

The supported justification reasons are:

  • Customer initiated access

  • Modified Customer initiated access

  • Google initiated system operation

  • Modified Google initiated system operation

  • No justification reason expected

  • Customer initiated support

  • Google initiated service

  • Third party data request

  • Google initiated review

  • Google response to production alert

  • No justification reason specified

  • Customer Authorized Workflow Servicing

  • Allow missing access justification

EKM Access Control List

This policy applies to all of the keys that are created in the associated KeySet for this Cloud Service Provider account, unless a policy at the key level overrides it. For coordinated keys, only the Cloud Service Provider-level permissions apply. The EKM access control list specifies the GCP identities and the permissions they have. You can specify identities by their service account email, for example:

apbyok2@kcv-project.iam.gserviceaccount.com

The supported permissions are: 

  • wrap

  • unwrap

  • asymmetricSign

  • getPublicKey

  • checkCryptoSpacePermissions

  • createKey

  • destroyKey