Stay organized with collections
Save and categorize content based on your preferences.
This page shows you how to resolve issues with Cloud External Key Manager (Cloud EKM) over
virtual private cloud (VPC).
In addition to the errors listed in the
Cloud EKM error reference, EKMs accessed over
VPC might experience additional errors.
Input errors
The following table describes errors caused by incorrect input and
suggests troubleshooting steps for these errors:
google.rpc.Status.message
violation[1].type(Error domain)
Troubleshooting
Permission denied when accessing the Service Directory. Ensure the Cloud EKM service account has access to the Service Directory resource in the VPC project.
The following table describes EKM system errors and troubleshooting suggestions:
google.rpc.Status.message
violation[1].type(Error domain)
Troubleshooting
Unable to use the Service Directory entry provided for the external
key manager. The data was incomplete or was not found in the
Service Directory service.
SD_RESOURCE_MALFORMED
If you manage your own EKM:
Ensure the network field of your Service Directory
endpoint is populated and that it matches the VPC network that you
use to reach your EKM.
Ensure the IP address and Port are set
correctly for your endpoint.
If your EKM is managed by a separate provider:
Contact your EKM provider to ensure the network
Service Directory endpoints are correctly set.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-28 UTC."],[],[],null,["# Troubleshoot EKM via VPC errors\n\nThis page shows you how to resolve issues with Cloud External Key Manager (Cloud EKM) over\nvirtual private cloud (VPC).\n\nIn addition to the errors listed in the\n[Cloud EKM error reference](/kms/docs/reference/ekm_errors), EKMs accessed over\nVPC might experience additional errors.\n\n### Input errors\n\nThe following table describes errors caused by incorrect input and\nsuggests troubleshooting steps for these errors:\n\n### External key management system errors\n\nThe following table describes EKM system errors and troubleshooting suggestions:"]]