Mods
GCP

Policy: GCP > Kubernetes Engine > Zone Cluster > Approved > Encryption at Rest > Customer Managed Key

The ID of a GCP KMS symmetric key that must be used as the encryption key for a GCP > Kubernetes Engine > Zone Cluster.

This policy will be evaluated by the Approved control. If a GCP Kubernetes Engine zone cluster is not encrypted with the specified key, it will be subject to the action specified in the GCP > Kubernetes Engine > Zone Cluster > Approved policy.

See Approved for more information.

Resource Types

This policy targets the following resource types:

Primary Policy

This policy is used with the following primary policy:

Controls

Policy Specification

Schema Type
string
Examples [YAML]
projects/my-kms-project/locations/us-east1/keyRings/my-keyring/cryptoKeys/my-key

Category

In Your Workspace

Developers