Closed karbyshevds closed 3 years ago
closes #4
kms_vault_id
Azure:
cloud.azure.kms_key_id param added, e.x.: "https://KEY_URL" kms_vault_id param added, e.x.: "/subscriptions/SUBSCRIPTION_ID/resourceGroups/RESOURCE_GROUP/providers/Microsoft.KeyVault/vaults/KEY_VAULT"
cloud.azure.kms_key_id
AWS:
cloud.aws.kms_key_arn param added
cloud.aws.kms_key_arn
GCP:
cloud.gcp.kms_key_id param added, e.x.: "projects/PROJECT/locations/LOCATION/keyRings/KEY_RING/cryptoKeys/KEY"
cloud.gcp.kms_key_id
closes #4
Changes
Cloud provider specific changes
GCP
AWS
Azure
kms_vault_id
is also required as parameter - looks like this is the only way to grant required permissions to encryption setProfile changes:
Azure:
cloud.azure.kms_key_id
param added, e.x.: "https://KEY_URL"kms_vault_id
param added, e.x.: "/subscriptions/SUBSCRIPTION_ID/resourceGroups/RESOURCE_GROUP/providers/Microsoft.KeyVault/vaults/KEY_VAULT"AWS:
cloud.aws.kms_key_arn
param addedGCP:
cloud.gcp.kms_key_id
param added, e.x.: "projects/PROJECT/locations/LOCATION/keyRings/KEY_RING/cryptoKeys/KEY"