GCP Requirements for BYOK

To use GCP with BYOK, you must create a new unique service account user in your GCP account. Service account creation is on the Service Account page (IAM & Admin > Service Account).

Important:  

  • Do not use an existing user account or existing access key. Create the service account with the following permissions see GCP BYOK Service Account Requirements.

  • Create an access key by logging in to GCP using the service account.

  • Do not use the access key more than one time.

  • Do not delete any access keys from the service account.

  • Do not attach the same GCP account to multiple KeyControl clusters.

  • Do not share the GCP BYOK service account.