An optional parameter to set the Customer-Supplied Encryption key for rewrite source object.
Application developers can generate their own encryption keys to protect the data in GCS. This is known as a Customer-Supplied Encryption key (CSEK). If the application provides a CSEK, GCS does not retain the key. The object data, the object CRC32 checksum, and its MD5 hash (if applicable) are all encrypted with this key, and the key is required to read any of these elements back.
Care must be taken to save and protect these keys, if lost, the data is not recoverable. Also, applications should avoid generating predictable keys, as this weakens the encryption.
This option is used only in rewrite operations and it defines the key used for the source object.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-04-02 UTC."],[[["This document details the `SourceEncryptionKey` structure used for handling Customer-Supplied Encryption Keys (CSEK) in Google Cloud Storage (GCS) for rewrite operations."],["The `SourceEncryptionKey` can be created from either a binary key or a base64-encoded key, both of which must be 32 bytes in length."],["Customer-Supplied Encryption Keys, used to encrypt data in GCS, are not retained by GCS and are required for reading the encrypted data back, so it's crucial to manage and secure these keys properly."],["The provided content lists the availability of `SourceEncryptionKey` across different versions, with the latest version being `2.37.0-rc`."],["The `SourceEncryptionKey` is an optional parameter that allows developers to set the Customer-Supplied Encryption key for the source object when rewriting."]]],[]]