public sealed class CustomerManagedEncryption : IMessage<CustomerManagedEncryption>, IEquatable<CustomerManagedEncryption>, IDeepCloneable<CustomerManagedEncryption>, IBufferMessage, IMessage
Reference documentation and code samples for the Secret Manager v1 API class CustomerManagedEncryption.
Configuration for encrypting secret payloads using customer-managed
encryption keys (CMEK).
Required. The resource name of the Cloud KMS CryptoKey used to encrypt
secret payloads.
For secrets using the
[UserManaged][google.cloud.secretmanager.v1.Replication.UserManaged]
replication policy type, Cloud KMS CryptoKeys must reside in the same
location as the [replica location][Secret.UserManaged.Replica.location].
For secrets using the
[Automatic][google.cloud.secretmanager.v1.Replication.Automatic]
replication policy type, Cloud KMS CryptoKeys must reside in global.
The expected format is projects/*/locations/*/keyRings/*/cryptoKeys/*.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-03-21 UTC."],[[["This documentation covers the `CustomerManagedEncryption` class within the Google Cloud Secret Manager v1 API, which is used for configuring encryption of secret payloads with customer-managed encryption keys (CMEK)."],["The latest version of the `CustomerManagedEncryption` class is 2.5.0, and the documentation provides details on multiple versions, from 1.3.0 to 2.5.0."],["The `CustomerManagedEncryption` class inherits from `Object` and implements interfaces such as `IMessage`, `IEquatable`, `IDeepCloneable`, and `IBufferMessage`."],["The `KmsKeyName` property, which is a required field, specifies the resource name of the Cloud KMS CryptoKey used for encryption, and its location must align with the secret's replication policy."],["The class includes constructors for creating new `CustomerManagedEncryption` objects, both with default values and by cloning existing instances."]]],[]]