Configure the Customer-Managed Encryption Key (CMEK) for an rewrite.
With CMEK you can use keys generated by Google Cloud's Key Management Service to encrypt the data in your objects. Use this option to configure the CMEK of an object created as part of a rewrite operation. Key names can be found from the Google Cloud console, and are in the projects/{PROJECT_ID}/locations/{LOCATION_ID}/keyRings/{KEY_RING_ID}/cryptoKeys/{CRYPTO_KEY_ID} format.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-04-02 UTC."],[[["The latest version available is 2.37.0-rc, with links to documentation for multiple versions of the library, including versions all the way down to 2.11.0."],["This content focuses on configuring Customer-Managed Encryption Keys (CMEK) for objects within Google Cloud Storage (GCS)."],["CMEK allows the use of keys from Google Cloud's Key Management Service to encrypt object data in rewrite operations."],["Key names for CMEK are in the format `projects/{PROJECT_ID}/locations/{LOCATION_ID}/keyRings/{KEY_RING_ID}/cryptoKeys/{CRYPTO_KEY_ID}`."],["The page includes information about a `well_known_parameter_name()` function, and a general introduction to CMEK in GCS can be found at the link that is provided."]]],[]]