Before you can use CSP Vault as a GCP EKM provider, you must set up the following parameters on the Cloud Service Provider Account details page.
EKM URI
The EKM URI is the URI GCP uses to access keys from the CSP Vault.
- If you deploy a single CSP Vault, set the EKM URI directly to that vault.
- If you deploy a cluster with multiple nodes, set the EKM URI to the load balancer.
For EKM via Internet, use the following format:
https://example.server.comFor EKM via VPC, use the following format:
https://<hostname>Key Access Justification Policy
We highly recommend creating a Key Access Justification policy at the Cloud Service Provider and KeySet level that specifies access justification reasons. These apply to all the keys created in this KeySet, unless the policy is specified at the key level, which overrides this policy.
The supported justification reasons are:
Customer initiated access
Modified Customer initiated access
Google initiated system operation
Modified Google initiated system operation
No justification reason expected
Customer initiated support
Google initiated service
Third party data request
Google initiated review
Google response to production alert
No justification reason specified
Customer Authorized Workflow Servicing
Allow missing access justification
EKM Access Control List
This policy applies to all of the keys that are created in the associated KeySet for this Cloud Service Provider account, unless a policy at the key level overrides it. For coordinated keys, only the Cloud Service Provider-level permissions apply. The EKM access control list specifies the GCP identities and the permissions they have. You can specify identities by their service account email, for example:
apbyok2@kcv-project.iam.gserviceaccount.comThe supported permissions are:
wrap
unwrap
asymmetricSign
getPublicKey
checkCryptoSpacePermissions
createKey
destroyKey