Mods
GCP

Policy: GCP > KMS > Crypto Key > Approved > Regions

A list of GCP regions in which GCP KMS crypto keys are approved for use.

The expected format is an array of regions names. You may use the '*' and '?' wildcard characters.

This policy will be evaluated by the Approved control. If a GCP KMS crypto key is created in a region that is not in the approved list, it will be subject to the action specified in the GCP > KMS > Crypto Key > Approved policy.

See Approved for more information.

Resource Types

This policy targets the following resource types:

Primary Policy

This policy is used with the following primary policy:

Controls

Policy Specification

Default template
{% if $.regions.value | length == 0 %} [] {% endif %}{% for item in $.regions.value %}- '{{ item }}'
{% endfor %}
Default template input
|
{
regions: policyValue(uri:"tmod:@turbot/gcp-kms#/policy/types/kmsApprovedRegionsDefault") {
value
}
}

Category

In Your Workspace

Developers