Google compute disk encryption with KMS key using Terraform











up vote
0
down vote

favorite












What is the Terraform syntax to encrypt the google_compute_disk using a custom managed KMS key in the Google cloud platform?



Referring the documentation and using the KMS key self_link for disk_encryption_key.raw_key seems to not work. The resulting disk generated shows the disk is encrypted via Google managed key.



Am using a wrong format?



Sample being used is given below:



**resource "google_compute_disk" "ext_disk" {
name = "testdisk"
type = "pd-ssd"
zone = "${var.zone}"
size = 16
labels {
environment = "${var.target_environment}"
}
disk_encryption_key {
raw_key = "${google_kms_crypto_key.crypto_key.self_link}"
}
}**









share|improve this question




























    up vote
    0
    down vote

    favorite












    What is the Terraform syntax to encrypt the google_compute_disk using a custom managed KMS key in the Google cloud platform?



    Referring the documentation and using the KMS key self_link for disk_encryption_key.raw_key seems to not work. The resulting disk generated shows the disk is encrypted via Google managed key.



    Am using a wrong format?



    Sample being used is given below:



    **resource "google_compute_disk" "ext_disk" {
    name = "testdisk"
    type = "pd-ssd"
    zone = "${var.zone}"
    size = 16
    labels {
    environment = "${var.target_environment}"
    }
    disk_encryption_key {
    raw_key = "${google_kms_crypto_key.crypto_key.self_link}"
    }
    }**









    share|improve this question


























      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      What is the Terraform syntax to encrypt the google_compute_disk using a custom managed KMS key in the Google cloud platform?



      Referring the documentation and using the KMS key self_link for disk_encryption_key.raw_key seems to not work. The resulting disk generated shows the disk is encrypted via Google managed key.



      Am using a wrong format?



      Sample being used is given below:



      **resource "google_compute_disk" "ext_disk" {
      name = "testdisk"
      type = "pd-ssd"
      zone = "${var.zone}"
      size = 16
      labels {
      environment = "${var.target_environment}"
      }
      disk_encryption_key {
      raw_key = "${google_kms_crypto_key.crypto_key.self_link}"
      }
      }**









      share|improve this question















      What is the Terraform syntax to encrypt the google_compute_disk using a custom managed KMS key in the Google cloud platform?



      Referring the documentation and using the KMS key self_link for disk_encryption_key.raw_key seems to not work. The resulting disk generated shows the disk is encrypted via Google managed key.



      Am using a wrong format?



      Sample being used is given below:



      **resource "google_compute_disk" "ext_disk" {
      name = "testdisk"
      type = "pd-ssd"
      zone = "${var.zone}"
      size = 16
      labels {
      environment = "${var.target_environment}"
      }
      disk_encryption_key {
      raw_key = "${google_kms_crypto_key.crypto_key.self_link}"
      }
      }**






      google-cloud-platform terraform terraform-provider-gcp






      share|improve this question















      share|improve this question













      share|improve this question




      share|improve this question








      edited Nov 20 at 9:30









      honk

      4,760114249




      4,760114249










      asked Nov 20 at 8:36









      Vineeth Kiv

      1




      1
























          1 Answer
          1






          active

          oldest

          votes

















          up vote
          0
          down vote













          KMS key is not really supported via Terraform to encrypt disk .This is currently tagged to enhancement with GCP's Terraform team .I was facing the same issue some time back and raised the query with them .Here is ticket number -https://github.com/terraform-providers/terraform-provider-google/issues/2234 .






          share|improve this answer





















            Your Answer






            StackExchange.ifUsing("editor", function () {
            StackExchange.using("externalEditor", function () {
            StackExchange.using("snippets", function () {
            StackExchange.snippets.init();
            });
            });
            }, "code-snippets");

            StackExchange.ready(function() {
            var channelOptions = {
            tags: "".split(" "),
            id: "1"
            };
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function() {
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled) {
            StackExchange.using("snippets", function() {
            createEditor();
            });
            }
            else {
            createEditor();
            }
            });

            function createEditor() {
            StackExchange.prepareEditor({
            heartbeatType: 'answer',
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader: {
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            },
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            });


            }
            });














            draft saved

            draft discarded


















            StackExchange.ready(
            function () {
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53389040%2fgoogle-compute-disk-encryption-with-kms-key-using-terraform%23new-answer', 'question_page');
            }
            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes








            up vote
            0
            down vote













            KMS key is not really supported via Terraform to encrypt disk .This is currently tagged to enhancement with GCP's Terraform team .I was facing the same issue some time back and raised the query with them .Here is ticket number -https://github.com/terraform-providers/terraform-provider-google/issues/2234 .






            share|improve this answer

























              up vote
              0
              down vote













              KMS key is not really supported via Terraform to encrypt disk .This is currently tagged to enhancement with GCP's Terraform team .I was facing the same issue some time back and raised the query with them .Here is ticket number -https://github.com/terraform-providers/terraform-provider-google/issues/2234 .






              share|improve this answer























                up vote
                0
                down vote










                up vote
                0
                down vote









                KMS key is not really supported via Terraform to encrypt disk .This is currently tagged to enhancement with GCP's Terraform team .I was facing the same issue some time back and raised the query with them .Here is ticket number -https://github.com/terraform-providers/terraform-provider-google/issues/2234 .






                share|improve this answer












                KMS key is not really supported via Terraform to encrypt disk .This is currently tagged to enhancement with GCP's Terraform team .I was facing the same issue some time back and raised the query with them .Here is ticket number -https://github.com/terraform-providers/terraform-provider-google/issues/2234 .







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Nov 20 at 11:48









                dream123

                23




                23






























                    draft saved

                    draft discarded




















































                    Thanks for contributing an answer to Stack Overflow!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid



                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.


                    To learn more, see our tips on writing great answers.





                    Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


                    Please pay close attention to the following guidance:


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid



                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.


                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function () {
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53389040%2fgoogle-compute-disk-encryption-with-kms-key-using-terraform%23new-answer', 'question_page');
                    }
                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    404 Error Contact Form 7 ajax form submitting

                    How to know if a Active Directory user can login interactively

                    Refactoring coordinates for Minecraft Pi buildings written in Python