Opt-in: --services kms
Encrypt and decrypt against the Cloud KMS API. Not a security boundary.
Key rings, symmetric keys and versions over gRPC and JSON. Key material is stored unencrypted.
Backed by: CloudBurrow CloudBurrow
In the console
What it covers
Cloud KMS is built by CloudBurrow, because Google publishes no emulator for it, and starts with --services kms. It serves symmetric keys, Encrypt and Decrypt and the version lifecycle. It is not a security boundary: key material is stored unencrypted.
- Key rings, symmetric keys and versions
- Encrypt and Decrypt over gRPC and JSON
- The version lifecycle: enable, disable, destroy and restore
- Automatic key rotation (#816) next release
- Tink with tink-go-gcpkms Verified
What's verified
Cloud KMS
16 of 35 RPCs Verified in v0.1.0
19 of 38 RPCs Verified on main next release
Not supported
- Not a security boundary: key material is stored unencrypted
- No IAM enforcement: v0.1.0 answers IAM methods with Unimplemented; on main policies are stored, never enforced #428
- No HSM, EKM or Autokey; symmetric encryption only
Source: docs/compatibility.md at main 82a2eb9.
Questions
Is it safe for real keys?
No. Cloud KMS here is not a security boundary: key material is stored unencrypted, and no IAM policy is enforced.
Link to this answer
Build against Google Cloud APIs, locally
Free and open source under Apache-2.0. No account, no sign-up, no Google Cloud bill.