Difference between revisions of "KMS PATH"

From wikieduonline
Jump to navigation Jump to search
Line 1: Line 1:
  
 
+
0) Obtain <code>[[KMS_PATH]]</code>
 
  [[gcloud kms keys list --location global --keyring sops]]
 
  [[gcloud kms keys list --location global --keyring sops]]
 
  NAME                                                                                          PURPOSE          ALGORITHM                   
 
  NAME                                                                                          PURPOSE          ALGORITHM                   
Line 11: Line 11:
 
  SOFTWARE                  1          DESTROYED  
 
  SOFTWARE                  1          DESTROYED  
  
 
+
1) [[Encrypt]] using <code>KMS_PATH</code>
  [[sops --encrypt --gcp-kms]] $[[KMS_PATH]] secret.yaml > secret.enc.yaml
+
* <code>[[sops --encrypt --gcp-kms]] $[[KMS_PATH]] secret.yaml > secret.yaml[[.sops]]</code>
  
 
== See also ==
 
== See also ==

Revision as of 10:35, 27 October 2022

0) Obtain KMS_PATH

gcloud kms keys list --location global --keyring sops
NAME                                                                                           PURPOSE          ALGORITHM                   
PROTECTION_LEVEL  LABELS  PRIMARY_ID  PRIMARY_STATE
projects/your-project/locations/global/keyRings/sops/cryptoKeys/sops-encryption-key            ENCRYPT_DECRYPT  GOOGLE_SYMMETRIC_ENCRYPTION  HSM                       
1           ENABLED
projects/your-project/locations/global/keyRings/sops/cryptoKeys/sops-encryption-key-data-lake  ENCRYPT_DECRYPT  GOOGLE_SYMMETRIC_ENCRYPTION  HSM                       
1           ENABLED
projects/your-project/locations/global/keyRings/sops/cryptoKeys/sops-key                       ENCRYPT_DECRYPT  GOOGLE_SYMMETRIC_ENCRYPTION  
SOFTWARE                  1           DESTROYED 

1) Encrypt using KMS_PATH

See also

Advertising: