gcloud storage service-agent

NAME
gcloud storage service-agent - manage a project's Cloud Storage service agent, which is used to perform Cloud KMS operations
SYNOPSIS
gcloud storage service-agent[--authorize-cmek=AUTHORIZE_CMEK][GCLOUD_WIDE_FLAG]
DESCRIPTION
gcloud storage service-agent displays the Cloud Storage serviceagent, which is used to perform Cloud KMS operations against your a default orsupplied project. If the project does not yet have a service agent,gcloudstorage service-agent creates one.
EXAMPLES
To show the service agent for your default project:
gcloudstorageservice-agent

To show the service account formy-project:

gcloudstorageservice-agent--project=my-project

To authorize your default project to use a Cloud KMS key:

gcloudstorageservice-agent--authorize-cmek=projects/key-project/locations/us-east1/keyRings/key-ring/cryptoKeys/my-key
FLAGS
--authorize-cmek=AUTHORIZE_CMEK
Adds appropriate encrypt/decrypt permissions to the specified Cloud KMS key.This allows the Cloud Storage service agent to write and read CloudKMS-encrypted objects in buckets associated with the service agent's project.
GCLOUD WIDE FLAGS
These flags are available to all commands:--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.

Run$gcloud help for details.

NOTES
This variant is also available:
gcloudalphastorageservice-agent

Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2025-05-07 UTC.