Opt-in: --services kms

Encrypt and decrypt against the Cloud KMS API. Not a security boundary.

Key rings, symmetric keys and versions over gRPC and JSON. Key material is stored unencrypted.

Backed by: CloudBurrow CloudBurrow

In the console

Cloud KMS key rings in the local console
Captured 2026-09-28 from main @5da2bd0. Product icons hidden.
A Cloud KMS key ring and its keys
Captured 2026-09-28 from main @5da2bd0. Product icons hidden.

What it covers

Cloud KMS is built by CloudBurrow, because Google publishes no emulator for it, and starts with --services kms. It serves symmetric keys, Encrypt and Decrypt and the version lifecycle. It is not a security boundary: key material is stored unencrypted.

  • Key rings, symmetric keys and versions
  • Encrypt and Decrypt over gRPC and JSON
  • The version lifecycle: enable, disable, destroy and restore
  • Automatic key rotation (#816) next release
  • Tink with tink-go-gcpkms Verified

What's verified

Cloud KMS

16 of 35 RPCs Verified in v0.1.0

Cloud KMS in v0.1.0: 16 Verified of 35

19 of 38 RPCs Verified on main next release

Cloud KMS on main: 19 Verified of 38
Every Cloud KMS RPC, with its test →

Not supported

  • Not a security boundary: key material is stored unencrypted
  • No IAM enforcement: v0.1.0 answers IAM methods with Unimplemented; on main policies are stored, never enforced #428
  • No HSM, EKM or Autokey; symmetric encryption only

Source: docs/compatibility.md at main 82a2eb9.

Questions

Is it safe for real keys?

No. Cloud KMS here is not a security boundary: key material is stored unencrypted, and no IAM policy is enforced.
Link to this answer

Build against Google Cloud APIs, locally

Free and open source under Apache-2.0. No account, no sign-up, no Google Cloud bill.

Get started