Cloud KMS with Autokey

Cloud KMS Autokey simplifies creating and using customer-managed encryption keys (CMEKs) by automating provisioning and assignment. With Autokey, key rings and keys are generated on-demand. Service accounts that use the keys to encrypt and decrypt resources are created and granted Identity and Access Management (IAM) roles when needed. Cloud KMS administrators retain full control and visibility of keys created by Autokey, without needing to pre-plan and create each resource. Using Autokey is simpler than provisioning keys yourself, and is the recommended choice if the keys created by Autokey meet all of your requirements.

Using keys generated by Autokey can help you consistently align with industry standards and recommended practices for data security, including the Multi-tenant Cloud HSM protection level, separation of duties, key rotation, location, and key specificity. Autokey creates keys that follow both general guidelines and guidelines specific to the resource type for Google Cloud services that integrate with Cloud KMS Autokey. After they are created, keys requested using Autokey function identically to other Cloud HSM keys with the same settings.

Autokey can also simplify usage of Terraform for key management, removing the need to run infrastructure-as-code with elevated key-creation privileges.

You can use Autokey with dedicated-project key storage (formerly known as centralized key management) or with same-project key storage (formerly known as delegated key management). To use Autokey with dedicated-project key storage, you must have an organization resource that contains a folder resource. When you use dedicated-project key storage, you enable Autokey for projects within a folder, and keys created by Autokey are created in the designated key project for that folder. When you use same-project key storage, you enable Autokey on a folder or project to let Autokey create keys in the same project as the resources that they protect.

For more information about organization and folder resources, see Resource hierarchy.

Cloud KMS Autokey is available in all Google Cloud locations where Cloud HSM is available. For more information about Cloud KMS locations, see Cloud KMS locations. There is no additional cost to use Cloud KMS Autokey. Keys created using Autokey are priced the same as any other Cloud HSM keys. For more information about pricing, see Cloud Key Management Service pricing.

For more information about Autokey, see Autokey overview.

Choose between Autokey and other encryption options

Cloud KMS with Autokey is like an autopilot for customer-managed encryption keys: it does the work on your behalf, on demand. You don't need to plan keys ahead of time or create keys that might never be needed. Keys and key usage are consistent. You can define where you want Autokey to be used and control who can use it. You retain full control of the keys created by Autokey. You can use manually-created Cloud KMS keys alongside keys created using Autokey. You can disable Autokey and continue to use the keys it created the same way you'd use any other Cloud KMS key.