gcloud beta kms ekm-connections create Stay organized with collections Save and categorize content based on your preferences.
- NAME
- gcloud beta kms ekm-connections create - create a new ekm connection
- SYNOPSIS
gcloud beta kms ekm-connections create(EKM_CONNECTION:--location=LOCATION)--hostname=HOSTNAME--server-certificates-files=[SERVER_CERTIFICATES,…]--service-directory-service=SERVICE_DIRECTORY_SERVICE[--endpoint-filter=ENDPOINT_FILTER][--crypto-space-path=CRYPTO_SPACE_PATH--key-management-mode=KEY_MANAGEMENT_MODE][GCLOUD_WIDE_FLAG …]
- DESCRIPTION
(BETA)Creates a new connection within the given location.- EXAMPLES
- The following command creates an ekm connection named
laplacewithin the locationus-central1:gcloudbetakmsekm-connectionscreatelaplace--location=us-central1--service-directory-service="foo"--endpoint-filter="foo > bar"--hostname="hostname.foo"--server-certificates-files=foo.pem,bar.pemThe following command creates an ekm connection named
laplacewithin the locationus-central1incloud-kmskeymanagement mode with the required crypto-space-path :gcloudbetakmsekm-connectionscreatelaplace--location=us-central1--service-directory-service="foo"--endpoint-filter="foo > bar"--hostname="hostname.foo"--key-management-mode=cloud-kms--crypto-space-path="foo"--server-certificates-files=foo.pem,bar.pem - POSITIONAL ARGUMENTS
- Ekmconnection resource - The KMS ekm connection resource. The arguments in thisgroup can be used to specify the attributes of this resource. (NOTE) Someattributes are not given arguments in this group but can be set in other ways.
To set the
projectattribute:- provide the argument
ekm_connectionon the command line with afully specified name; - set the property
core/project.
This must be specified.
EKM_CONNECTION- ID of the ekmconnection or fully qualified identifier for the ekmconnection.
To set the
ekmconnectionattribute:- provide the argument
ekm_connectionon the command line.
This positional argument must be specified if any of the other arguments in thisgroup are specified.
- provide the argument
--location=LOCATION- The Google Cloud location for the ekmconnection.
To set the
locationattribute:- provide the argument
ekm_connectionon the command line with afully specified name; - provide the argument
--locationon the command line.
- provide the argument
- provide the argument
- Ekmconnection resource - The KMS ekm connection resource. The arguments in thisgroup can be used to specify the attributes of this resource. (NOTE) Someattributes are not given arguments in this group but can be set in other ways.
- REQUIRED FLAGS
--hostname=HOSTNAME- The hostname of the EKM replica used at TLS and HTTP layers.
--server-certificates-files=[SERVER_CERTIFICATES,…]- A list of filenames of leaf server certificates used to authenticate HTTPSconnections to the EKM replica in PEM format. If files are not in PEM, theassumed format will be DER.
--service-directory-service=SERVICE_DIRECTORY_SERVICE- The resource name of the Service Directory service pointing to an EKM replica.
- OPTIONAL FLAGS
--endpoint-filter=ENDPOINT_FILTER- The filter applied to the endpoints of the resolved service. If no filter isspecified, all endpoints will be considered.
- Specifies the key management mode for the EkmConnection and associated fields.
--crypto-space-path=CRYPTO_SPACE_PATH- Crypto space path for the EkmConnection. Required during EkmConnection creationif
--key-management-mode=cloud-kms. --key-management-mode=KEY_MANAGEMENT_MODE- Key management mode of the ekm connection. An EkmConnection in
cloud-kmsmode means Cloud KMS will attempt to create and managethe key material that resides on the EKM for crypto keys created with thisEkmConnection. An EkmConnection inmanualmode means the externalkey material will not be managed by Cloud KMS. Omitting the flag defaults tomanual.KEY_MANAGEMENT_MODEmust be one of:manual,cloud-kms.
- GCLOUD WIDE FLAGS
- These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$gcloud helpfor details. - NOTES
- This command is currently in beta and might change without notice. Thesevariants are also available:
gcloudkmsekm-connectionscreategcloudalphakmsekm-connectionscreate
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-05-07 UTC.