- HTTP request
- Path parameters
- Request body
- Response body
- Authorization scopes
- IAM Permissions
- Try it!
Returns the Shielded Instance Identity of an instance
HTTP request
GET https://compute.googleapis.com/compute/beta/projects/{project}/zones/{zone}/instances/{instance}/getShieldedInstanceIdentity
The URL uses gRPC Transcoding syntax.
Path parameters
Parameters | |
---|---|
project |
Project ID for this request. |
zone |
The name of the zone for this request. |
instance |
Name or id of the instance scoping this request. |
Request body
The request body must be empty.
Response body
A Shielded Instance Identity.
If successful, the response body contains data with the following structure:
JSON representation |
---|
{ "kind": string, "signingKey": { "ekCert": string, "ekPub": string }, "encryptionKey": { "ekCert": string, "ekPub": string } } |
Fields | |
---|---|
kind |
[Output Only] Type of the resource. Always |
signing |
An Attestation Key (AK) made by the RSA 2048 algorithm issued to the Shielded Instance's vTPM. |
signing |
A PEM-encoded X.509 certificate. This field can be empty. |
signing |
A PEM-encoded public key. |
encryption |
An Endorsement Key (EK) made by the RSA 2048 algorithm issued to the Shielded Instance's vTPM. |
encryption |
A PEM-encoded X.509 certificate. This field can be empty. |
encryption |
A PEM-encoded public key. |
Authorization scopes
Requires one of the following OAuth scopes:
https://www.googleapis.com/auth/compute.readonly
https://www.googleapis.com/auth/compute
https://www.googleapis.com/auth/cloud-platform
For more information, see the Authentication Overview.
IAM Permissions
In addition to any permissions specified on the fields above, authorization requires one or more of the following IAM permissions:
compute.instances.getShieldedInstanceIdentity
To find predefined roles that contain those permissions, see Compute Engine IAM Roles.