CMEK and Encryption keys usage

30 views
Skip to the first unread message

Ruban Siva

unread,
28 Aug 2020, 2:28:33 pm28/08/20
to Google Cloud SQL discuss
Hi,
I understand with CloudSQL, can encrypt the data at persistence using encryption key using CMEK so it's managed by the end user.
Does this only apply to during update/insert or is it using read too? 
Just wondering how it works during data retrieval.

Mohammad I (Cloud Platform Support)

unread,
29 Aug 2020, 6:45:43 pm29/08/20
to Google Cloud SQL discuss

Hello Ruban, 

This document outlines when Cloud SQL interacts with CMEK keys such as during Instance creation, Backup creation, Instance restore, Replica creation, Clone creation and Instance update. 

As mentioned here,  CMEK can not be used to encrypt user data in transit, such as user queries and responses.

I have noticed you have also asked the same question at the StackOverflow thread where one of the Google Cloud Support agents has responded to your query as well. 
Reply all
Reply to author
Forward
0 new messages