Configure the Customer-Managed Encryption Key (CMEK) for an rewrite.
With CMEK you can use keys generated by Google Cloud's Key Management Service to encrypt the data in your objects. Use this option to configure the CMEK of an object created as part of a rewrite operation. Key names can be found from the Google Cloud console, and are in the projects/{PROJECT_ID}/locations/{LOCATION_ID}/keyRings/{KEY_RING_ID}/cryptoKeys/{CRYPTO_KEY_ID} format.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-14 UTC."],[[["\u003cp\u003eThe latest version available is 2.37.0-rc, which is accessible via a specified URL.\u003c/p\u003e\n"],["\u003cp\u003eThis webpage provides access to various versions of documentation, ranging from version 2.11.0 up to the latest release candidate, 2.37.0-rc.\u003c/p\u003e\n"],["\u003cp\u003eThe documentation relates to the \u003ccode\u003eDestinationKmsKeyName\u003c/code\u003e structure within Google Cloud Storage (GCS) reference material, which concerns configuring Customer-Managed Encryption Keys (CMEK).\u003c/p\u003e\n"],["\u003cp\u003eCMEK enables users to use keys managed by Google Cloud's Key Management Service to encrypt data in GCS objects.\u003c/p\u003e\n"],["\u003cp\u003eThe page includes a link to an external resource that gives a broad introduction to CMEK in GCS.\u003c/p\u003e\n"]]],[],null,[]]