If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: docs.cloud.google.com/compute/docs/disks/customer-managed-encryption - Protect resources with Cloud K.

site address: docs.cloud.google.com/compute/docs/disks/customer-managed-encryption

site title: Protect resources with Cloud KMS keys     Compute Engine     Google Cloud Documentation

Our opinion (on Monday 20 July 2026 0:40:22 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:


page from cache: 11 hours ago
Meta tags:

Headings (most frequently used words):

gcloud, rest, cmek, console, disk, with, key, snapshot, and, or, create, from, encrypted, the, resources, on, for, required, permissions, cloud, kms, encrypt, new, vm, remove, revocation, protect, keys, stay, organized, collections, save, categorize, content, based, your, preferences, before, you, begin, encryption, specifications, limitations, manual, automated, creation, persistent, hyperdisk, balanced, in, confidential, mode, an, imported, image, attaching, boot, to, rotate, change, disable, destroy, what, next, roles, manually, ring, impact, of, configure, shutdown, products, pricing, support, engage, this, task,

Text of the page (most frequently used words):
the (691), disk (239), #create (228), key (226), and (164), for (149), cloud (143), compute (140), you (134), snapshot (131), with (122), vms (108), that (97), disks (97), kms (89), use (85), google (75), region (72), projects (70), name (68), zone (64), about (63), new (62), troubleshoot (62), snapshots (61), instance (59), from (57), using (57), encrypted (54), gcloud (51), can (51), image (50), encryption (49), manage (47), project (46), encrypt (45), type (43), cmek (43), your (43), engine (43), following (41), hyperdisk (40), server (39), view (38), images (37), keys (37), configure (36), key_ring (36), zones (35), project_id (35), source (35), storage (35), set (34), resources (33), windows (33), mig (33), post (32), overview (32), change (31), performance (31), locations (30), kms_project_id (30), global (29), managed (29), instances (29), disk_name (29), machine (29), location (28), reservation (27), snapshot_name (26), where (26), this (25), com (25), creation (25), persistent (24), request (24), keyrings (24), cryptokeys (24), https (23), googleapis (23), default (23), when (23), located (23), scoped (23), specify (22), replace (22), regional (22), network (21), method (21), console (21), service (21), sql (21), example (20), management (20), access (20), monitor (20), standard (19), attached (19), used (19), update (19), boot (18), want (18), rest (18), kmskeyname (18), linux (18), custom (18), confidential (18), gpu (18), are (17), command (17), shutdown (17), creating (17), enable (17), policies (16), mode (16), configuration (16), data (16), apply (16), remove (16), reservations (16), see (15), more (15), revocation (15), select (15), rotate (15), virtual (15), groups (15), ssh (15), recommendations (15), down (14), information (14), insert (14), sole (14), agent (14), regions (14), updatekmskey (14), optional (14), ring (14), contains (14), workload (14), host (14), load (14), connect (14), stop (13), include (13), protect (13), regionally (13), delete (13), balanced (13), bulk (13), microsoft (13), cluster (13), permissions (12), resource (12), workloads (12), volumes (12), add (12), choose (12), availability (12), best (12), must (11), customer (11), cli (11), property (11), uses (11), running (11), version (11), flag (11), click (11), existing (11), import (11), settings (11), types (11), roles (11), based (11), practices (11), stateful (11), debian (10), required (10), security (10), zonal (10), diskencryptionkey (10), customized (10), manually (10), time (10), instant (10), multiple (10), install (10), metadata (10), migs (10), machines (10), migrate (10), logs (10), all (9), page (9), template (9), created (9), templates (9), networking (9), disable (9), same (9), new_key_name (9), only (9), multi (9), tpu (9), h4d (9), application (9), licenses (9), tenant (9), openshift (9), start (9), hpc (9), samples (8), license (8), properties (8), construct (8), policy (8), includes (8), note (8), during (8), owned (8), different (8), one (8), operation (8), key_project_id (8), disk_type (8), snapshot_type (8), source_disk_name (8), backup (8), source_image (8), role (8), authentication (8), run (8), cpu (8), login (8), optimize (8), internal (8), disaster (8), recovery (8), high (8), guest (8), flexibility (8), dns (8), optimized (8), thumb (7), other (7), send (7), sourceimage (7), section (7), tenancy (7), automatically (7), then (7), such (7), encrypting (7), instead (7), migration (7), get (7), operations (7), globally (7), predefined (7), source_zone (7), services (7), demand (7), across (7), local (7), usage (7), commitments (7), startup (7), balancing (7), benchmark (7), idle (7), addresses (7), scale (7), deploy (7), back (7), mysql (7), maintenance (7), events (6), code (6), understand (6), need (6), under (6), details (6), after (6), configured (6), true (6), revoked (6), not (6), have (6), between (6), iam (6), copy (6), process (6), api (6), preview (6), operating (6), don (6), number (6), ssd (6), parameter (6), snapshot_scope_region (6), storage_location (6), snapshot_key (6), key_region (6), owns (6), hsm (6), accounts (6), errors (6), identity (6), apis (6), options (6), updates (6), files (6), nested (6), gpus (6), applications (6), group (6), pools (6), failover (6), extension (6), transfer (6), spot (6), action (5), system (5), shut (5), attach (5), external (5), will (5), machine_type (5), prevent (5), also (5), perform (5), archive (5), runs (5), list (5), sourcesnapshot (5), source_region (5), image_name (5), file (5), override (5), make (5), environment (5), how (5), monitoring (5), databases (5), future (5), drivers (5), virtualization (5), nvidia (5), placement (5), node (5), highly (5), available (5), build (5), modify (5), capacity (5), schedules (5), audit (5), symphony (5), email (5), scripts (5), manager (5), systems (5), enhanced (5), capabilities (5), restore (5), control (5), workstation (5), faq (5), flex (5), português (4), español (4), sign (4), support (4), machinetype (4), initializeparams (4), keyrevocationactiontype (4), menu (4), vm_name (4), within (4), destroy (4), automatic (4), which (4), these (4), rotation (4), beta (4), full (4), either (4), yyyyyyyyyyyyy (4), yyyyyyyy (4), schedule (4), device (4), disktypes (4), supports (4), storagelocations (4), source_project_id (4), destination_project_id (4), bullseye (4), v20231115 (4), size (4), autokey (4), manual (4), online (4), generation (4), infrastructure (4), cmeks (4), has (4), documentation (4), grant (4), account (4), permission (4), development (4), authenticate (4), provider (4), plan (4), through (4), tools (4), distributed (4), issues (4), ubuntu (4), bandwidth (4), tcp (4), pmu (4), share (4), upgrade (4), live (4), autoscaling (4), cross (4), requests (4), calendar (4), single (4), metrics (4), health (4), active (4), clusters (4), containers (4), container (4), database (4), postgresql (4), extensions (4), work (4), suspend (4), resize (4), graceful (4), plans (4), replication (4), review (4), bound (4), terms (3), status (3), content (3), its (3), apache (3), networks (3), define (3), expand (3), begin (3), alternatively (3), machinetypes (3), restart (3), helps (3), revoke (3), setting (3), enabled (3), shuts (3), disabling (3), effects (3), any (3), was (3), follow (3), steps (3), help (3), provide (3), protecting (3), dek (3), doesn (3), versions (3), value (3), format (3), directory (3), reference (3), continue (3), specified (3), snapshot_project_id (3), enter (3), imported (3), because (3), store (3), sourcedisk (3), snapshottype (3), snapshotencryptionkey (3), alternative (3), event (3), unless (3), enableconfidentialcompute (3), provisioned (3), throughput (3), provisioning (3), cloning (3), clones (3), first (3), decrease (3), latency (3), failure (3), user (3), project_number (3), credentials (3), guides (3), observability (3), analytics (3), troubleshooting (3), pro (3), serial (3), configurations (3), patterns (3), higher (3), discounts (3), cuds (3), scalable (3), resilient (3), autoscale (3), balancer (3), testing (3), ibm (3), spectrum (3), deploying (3), prepare (3), deployment (3), rhel (3), certificates (3), query (3), state (3), increase (3), lifecycle (3), design (3), non (3), pool (3), move (3), workstations (3), series (3), tpus (3), product (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), third (2), site (2), youtube (2), center (2), started (2), pricing (2), products (2), last (2), updated (2), 2026 (2), utc (2), otherwise (2), licensed (2), feedback (2), learn (2), next (2), instancetemplates (2), networkinterfaces (2), family (2), body (2), fields (2), open (2), protected (2), public (2), hours (2), deleting (2), reverse (2), preceding (2), impact (2), still (2), until (2), decrypt (2), contents (2), encrypts (2), requirements (2), without (2), response (2), represents (2), progress (2), operation_name (2), reduce (2), methods (2), resizing (2), form (2), disk_alias (2), shown (2), supplied (2), imageencryptionkey (2), compressed (2), source_disk (2), drop (2), before (2), recommends (2), features (2), createsnapshot (2), stored (2), allowed (2), defined (2), choice (2), volume (2), indicate (2), fails (2), able (2), accidental (2), deletion (2), task (2), similarly (2), computing (2), iops (2), assign (2), replica (2), rings (2), provision (2), they (2), deleted (2), bare (2), metal (2), offline (2), were (2), spread (2), west1 (2), own (2), limitations (2), additional (2), specifications (2), related (2), administrator (2), might (2), ensure (2), cloudkms (2), cryptokeyencrypterdecrypter (2), gserviceaccount (2), already (2), idp (2), federated (2), supported (2), owner (2), serviceusage (2), sdk (2), languages (2), frameworks (2), costs (2), industry (2), solutions (2), hybrid (2), multicloud (2), pipelines (2), hosting (2), quota (2), commitment (2), consumption (2), registration (2), sles (2), export (2), port (2), collecting (2), nodes (2), report (2), arm (2), core (2), rdp (2), general (2), app (2), analyze (2), visible (2), cores (2), committed (2), underutilized (2), insights (2), utilization (2), web (2), autohealing (2), iis (2), shared (2), reserve (2), autoscaler (2), autoscalers (2), activity (2), kubernetes (2), place (2), redis (2), writer (2), always (2), alwayson (2), synchronization (2), switch (2), byol (2), payg (2), byos (2), changes (2), families (2), guide (2), securing (2), simulate (2), topology (2), together (2), repairs (2), repair (2), check (2), failures (2), suspended (2), stopped (2), target (2), distribution (2), physical (2), cancel (2), once (2), limit (2), interfaces (2), ipv6 (2), static (2), basic (2), consistent (2), appliances (2), asynchronous (2), names (2), mount (2), memory (2), extreme (2), organization (2), advanced (2), rdma (2), specific (2), preemptible (2), models (2), rtx (2), vws (2), constraints (2), accelerator (2), technology (2), areas (2), close (2), subscribe, newsletter, our, decade, climate, join, cookies, privacy, tech, twitter, blog, engage, training, certification, architecture, getting, github, release, notes, community, forums, contact, sales, marketplace, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, sample, incorrectinformationorsamplecode, missing, missingtheinformationsamplesineed, otherdown, tell, except, noted, java, registered, trademark, oracle, affiliates, developers, creative, commons, attribution, what, accessconfigs, one_to_one_nat, read_write, explicitly, minimal, looks, like, instance_template_name, image_project, machine_type_zone, creates, again, does, helping, enabling, cannot, protects, affected, follows, accessible, trigger, there, delay, hour, usable, decrypting, may, order, destroying, quickly, longer, removing, referred, revoking, currently, primary, containing, new_kms_key, changing, meet, compliance, downtime, rotating, previous, succeeded, 100, poll, determine, call, successful, making, item, patch, potential, consequences, being, compromised, recommend, regular, unique, alias, mounting, chooses, assigned, field, applicable, dev, devicename, yes, attaching, partial, url, reside, rawdisk, http, tar, sourcetype, raw, uri, upload, compress, try, won, original, capture, clean, failsafe, unsuccessful, caution, incremental, well, convert, completely, n2d, isn, standalone, replicas, two, specifying, supplying, described, simplifies, managing, automating, assignment, ahead, generated, part, automated, a4x, c4a, c4d, fourth, second, unsupported, recommended, approach, prevents, cases, depend, domains, geographical, terminated, ensures, isolation, increases, reliability, working, them, hardware, backed, enclaves, aes, 256, itself, give, exact, necessary, ask, granting, folders, organizations, correct, principal, result, important, cryptokey, encrypter, decrypter, even, binding, member, serviceaccount, haven, verifies, selecting, installed, previously, sure, latest, components, init, installation, initialize, tab, case, reviewing, relevant, likely, admin, serviceusageadmin, decide, whether, going, ids, numbers, identifying, document, provides, known, save, categorize, preferences, stay, organized, collections, home, concurrent, renewal, nvme, common, pay, viewing, output, diagnostic, sudoers, screenshots, generate, bug, blackwell, soft, lockups, bus, locks, rescue, inaccessible, dumps, kernel, panic, fstab, unresponsive, suspension, reboots, shutdowns, connectivity, tips, nics, dpdk, improve, resiliency, communication, compact, idpf, interface, irdma, driver, nic, customize, threads, per, sustained, merge, split, extend, renew, purchase, cost, savings, dynamic, overcommit, cpus, floating, reliable, udp, backends, routing, scaling, consuming, consume, combine, cud, allow, sharing, decisions, signals, serving, predictions, organize, labels, states, observe, reports, tensorflow, inference, tensorrt5, learning, monte, carlo, spark, forwarding, others, integrate, clustering, exchange, 2016, sharepoint, strategies, passive, inactive, setups, built, integrations, validation, deployed, transition, test, hammerdb, bucket, aws, ec2, pacemaker, s2d, block, netapp, hot, standby, drbd, architectures, client, private, address, mailjet, mailgun, sendgrid, sending, blue, green, deployments, lamp, joomla, asp, net, interactive, mongodb, flask, terraform, servers, over, mtls, random, generator, virtio, rng, accurate, protocol, ntp, append, els, restrictions, packages, deprecate, trusted, red, hat, knowledgebase, functionality, risks, vpc, controls, kek, secure, expiration, shielded, attributes, handle, notices, faulty, unmanaged, affect, preserved, turn, off, alternate, repairing, maintain, upgrades, selectively, applying, accelerate, out, outage, rebalance, reenable, proactive, redistribution, shape, distribute, info, edit, rename, reset, resume, referrers, uuid, recover, corrupted, duplicate, alerts, backups, vss, protection, considerations, synchronous, consistency, failback, replicate, limits, evaluate, symbolic, links, practice, ram, exapools, verify, ptr, record, rates, tags, restrict, automate, password, require, powershell, sac, securely, apps, root, vpn, bastion, iap, connection, browser, connections, iso, prerequisites, importing, exporting, bring, path, detach, reattach, constraint, accounting, examples, slurm, reserved, team, slice, slices, adds, scenarios, deterministic, base, ready, aci, preempted, historical, similar, displays, ops, logging, subnet, gpudirect, ultra, minimum, platform, hostname, quickstarts, office, licensing, premium, strategy, gemini, accelerators, platforms, scores, purpose, discover, free, skip, main,


Text of the page (random words):
ces monitor vm and sole tenant node usage observe and monitor vms monitor gpu performance monitor gpu performance on linux vms monitor gpu performance on windows vms monitor disks monitor disk health monitor the replica states of regional disks monitor disks list of metrics for pools monitor pools monitor reservations organize resources using labels scale autoscale groups of vms about autoscaling groups of vms create and manage autoscalers scale based on cpu utilization scale based on predictions scale based on load balancing serving capacity scale based on monitoring metrics scale based on schedules use an autoscaling policy with multiple signals manage autoscalers understand autoscaler decisions view autoscaler logs autoscale node groups reserve vm capacity choose a reservation type sharing reservations best practices for shared reservations allow a project to share reservations on demand reservations about on demand reservations create an on demand reservation for a single project for multiple projects combine an on demand reservation with a cud modify an on demand reservation delete an on demand reservation future reservations about future reservations create a reservation request for a single project for multiple projects modify a reservation request delete a reservation request future reservations in calendar mode about future reservations in calendar mode create a reservation request in calendar mode delete a reservation request in calendar mode view reservations or reservation requests consume a reservation prevent vms from consuming reservations load balancing about load balancing and scaling add an instance group to a load balancer request routing to a multi region external https load balancer cross region load balancing for microsoft iis backends set up internal tcp udp load balancing build reliable and scalable applications use autohealing for highly available applications use load balancing for highly available applications use autoscaling for highly scalable applications globally autoscale a web service on compute engine patterns for scalable and resilient applications patterns for using floating ip addresses on compute engine optimize resource utilization use recommendations to manage resources apply machine type recommendations to vms configure machine type recommendations apply machine type recommendations to migs view and apply idle resources recommendations view and understand vm insights view and understand mig insights manage idle vm recommendations idle vm recommendations overview view and apply idle vm recommendations configure idle vm recommendations manage reservation recommendations reservation recommendations overview view and apply idle reservation recommendations view and apply underutilized reservation recommendations configure idle reservation recommendations configure underutilized reservation recommendations overcommit cpus on sole tenant vms manual live migration about manual live migration manually live migrate vms share sole tenant node groups next generation dynamic resource management cost savings get discounts for committed usage about commitments and committed use discounts cuds resource based cuds purchase resource based commitments without attached reservations with attached reservations for os licenses manage resource based commitments renew commitments automatically extend commitment terms merge and split commitments upgrade commitments share resource based cuds across projects get discounts for sustained usage disk performance optimize hyperdisk performance optimize persistent disk performance optimize local ssd performance workload performance set the number of threads per core customize the number of visible cpu cores analyze the cpu performance using the pmu pmu overview enable the pmu in vms manage the pmu in vms network performance network bandwidth use google virtual nic use irdma network driver use idpf network interface configure a vm with higher bandwidth reduce latency by using compact placement policies optimize tcp network communication optimize tcp network performance optimize tcp network resiliency benchmark higher bandwidth vms optimize app latency with load balancing use dpdk to improve network performance network performance and gpu vms networking and gpu machines use higher network bandwidth patterns for using multiple host nics troubleshoot general tips troubleshoot connectivity troubleshoot rdp troubleshoot ssh troubleshoot os login troubleshoot vms troubleshoot vm operations troubleshoot vm creation troubleshoot resource availability errors troubleshoot bulk api vm creation troubleshoot vm reboots and shutdowns troubleshoot vm suspension troubleshoot vm updates troubleshoot unresponsive vms troubleshoot vm startup troubleshoot fstab errors troubleshoot kernel panic collecting core dumps rescue an inaccessible vm troubleshoot cpu bus locks troubleshoot cpu soft lockups troubleshoot vm configurations troubleshoot arm vms troubleshoot gpu vms troubleshoot nvidia gpu errors generate a nvidia bug report for blackwell gpus troubleshoot nested virtualization troubleshoot using vm screenshots troubleshoot sole tenant nodes troubleshoot vm performance issues troubleshoot sudoers files troubleshoot windows vms troubleshoot windows vms collecting diagnostic information troubleshoot using the serial console troubleshoot using the serial console viewing serial port output troubleshoot instance groups troubleshoot managed instance groups migs troubleshoot os management troubleshoot licenses troubleshoot image import and export troubleshooting sles pay as you go registration troubleshooting ubuntu pro registration troubleshoot metadata server troubleshoot metadata server troubleshoot networking issues troubleshoot common networking issues troubleshoot network drivers troubleshoot vm performance issues troubleshoot storage troubleshoot disk creation troubleshoot full disks and disk resizing troubleshoot disk encryption troubleshoot nvme disks troubleshoot instant snapshots troubleshoot standard snapshots troubleshoot reservations and commitments troubleshoot reservation creation troubleshoot reservation consumption troubleshooting reservation monitoring troubleshoot reservation updates troubleshoot future reservation creation and updates troubleshoot automatic commitment renewal troubleshoot quota errors troubleshoot concurrent operation quota errors troubleshoot workload authentication troubleshoot default service accounts troubleshoot workload to workload authentication ai and ml application development application hosting compute data analytics and pipelines databases distributed hybrid and multicloud industry solutions migration networking observability and monitoring security storage access and resources management costs and usage management infrastructure as code sdk languages frameworks and tools home documentation compute compute engine guides send feedback protect resources with cloud kms keys stay organized with collections save and categorize content based on your preferences this document provides information about how to use manually created cloud key management service cloud kms keys to encrypt disks and other storage related resources keys managed in cloud kms are known as customer managed encryption keys cmeks you can use cmeks to encrypt compute engine resources such as disks machine images instant snapshots and standard snapshots before you begin understand disks images standard snapshots and virtual machine vm instances decide whether you are going to run compute engine and cloud kms in the same google cloud project or in different projects for information about google cloud project ids and project numbers see identifying projects for the google cloud project that runs cloud kms do the following enable the cloud kms api roles required to enable apis to enable apis you need the serviceusage services enable permission if you created the project then you likely already have this permission through the owner role roles owner otherwise you can get this permission through the service usage admin role roles serviceusage serviceusageadmin learn how to grant roles enable the api to create a new hyperdisk balanced volume in confidential mode ensure your use case is supported by reviewing the relevant limitations and supported regions if you haven t already set up authentication authentication verifies your identity for access to google cloud services and apis to run code or samples from a local development environment you can authenticate to compute engine by selecting one of the following options select the tab for how you plan to use the samples on this page console when you use the google cloud console to access google cloud services and apis you don t need to set up authentication gcloud install the google cloud cli after installation initialize the google cloud cli by running the following command gcloud init if you re using an external identity provider idp you must first sign in to the gcloud cli with your federated identity note if you installed the gcloud cli previously make sure you have the latest version by running gcloud components update set a default region and zone rest to use the rest api samples on this page in a local development environment you use the credentials you provide to the gcloud cli install the google cloud cli if you re using an external identity provider idp you must first sign in to the gcloud cli with your federated identity for more information see authenticate for using rest in the google cloud authentication documentation required roles and permissions the compute engine service agent has the following form service project_number compute system iam gserviceaccount com you can use the google cloud cli to assign the role gcloud projects add iam policy binding kms_project_id member serviceaccount service project_number compute system iam gserviceaccount com role roles cloudkms cryptokeyencrypterdecrypter replace the following kms_project_id the id of your google cloud project that runs cloud kms even if this is the same project running compute engine project_number the project number not google cloud project id of your google cloud project that runs the compute engine resources to ensure that the compute engine service agent has the necessary permissions to protect resources by using cloud kms keys ask your administrator to grant the cloud kms cryptokey encrypter decrypter roles cloudkms cryptokeyencrypterdecrypter iam role to the compute engine service agent on your project important you must grant this role to the compute engine service agent not to your user account failure to grant the role to the correct principal might result in permission errors for more information about granting roles see manage access to projects folders and organizations this predefined role contains the permissions required to protect resources by using cloud kms keys to see the exact permissions that are required expand the required permissions section required permissions the following permissions are required to protect resources by using cloud kms keys to rotate an encryption key protecting a disk compute disks updatekmskey to rotate an encryption key protecting a snapshot compute snapshots updatekmskey your administrator might also be able to give the compute engine service agent these permissions with custom roles or other predefined roles encryption specifications the cloud kms keys used to help protect your data in compute engine are aes 256 keys these keys are key encryption keys and they encrypt the data encryption keys that encrypt your data not the data itself the data on the disks is encrypted using google owned and google managed encryption keys for specifications related to the default encryption in google cloud see default encryption at rest in the security documentation with confidential mode for hyperdisk balanced and cloud hsm the data encryption key dek has additional security properties with hardware backed enclaves limitations you can t encrypt existing resources with cmeks you can only encrypt disks images and snapshots with cmeks when you create them when you create a disk from a cmek encrypted instant snapshot you must specify the key used to encrypt the source disk you don t have to specify the key when working with other cmek encrypted resources such as disk clones and standard snapshots when you create a regionally scoped snapshot preview from a disk encrypted with a cmek you must create the snapshot with a regional cmek that s in the same location as the snapshot this ensures regional isolation of your snapshot and increases your snapshot s reliability you can t use your own keys with local ssd disks because the keys are managed by google cloud infrastructure and deleted when the vm is terminated regional resources disks can only be encrypted by a key in one of the following cloud kms locations a key in the same region as the disk a multi regional key in the same geographical location as the disk a key in the global location for example a disk in zone us west1 a can be encrypted by a key in the global location the us west1 region or the us multi region global resources such as images and snapshots can be encrypted by keys in any location for more information see types of locations for cloud kms note we recommended using keys in the same location as the resources you want to protect this approach helps to decrease latency and prevents cases where resources depend on services spread across multiple failure domains you can t change or remove the encryption key for an image or instant snapshot you can t remove a disk or snapshot s encryption key or change the key from a cmek to a google owned and managed key instead create a copy of the disk or snapshot and specify a new encryption type for the copy for more information see remove the cmek from a disk and remove the cmek from a snapshot you can t rotate or change the cmek of online confidential hyperdisk volumes or online hyperdisk volumes that are attached to unsupported machine types you can rotate or change the cmek on only the following disk types all persistent disk volumes hyperdisk volumes that were created from an instant snapshot offline hyperdisk volumes offline confidential hyperdisk volumes online hyperdisk volumes that are attached to first or second generation machine types online hyperdisk volumes that are attached to the following third or fourth generation machine types a3 a4 z3 h4d all tpu versions bare metal a4x c4 c4a c4d c3 and x4 machine types you can t change the key for hyperdisk volumes that you created by cloning a disk unless you have deleted the source disk and all other clones of the source disk manual or automated key creation you can either create cloud kms keys manually or use cloud kms autokey autokey simplifies creating and managing cloud kms keys by automating provisioning and assignment with autokey you don t need to provision key...
Images from subpage: "docs.cloud.google.com/compute/docs/images/image-management-b... " Verify
Images from subpage: "docs.cloud.google.com/compute/docs/images/image-families-bes... " Verify
Images from subpage: "docs.cloud.google.com/compute/docs/images/premium/access-rhe... " Verify
Images from subpage: "docs.cloud.google.com/compute/docs/images/managing-access-cu... " Verify
Images from subpage: "docs.cloud.google.com/compute/docs/images/restricting-image-... " Verify

Verified site has: 733 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
201-205 206-210 211-215 216-220 221-225 226-230 231-235 236-240 241-245 246-250
251-255 256-260 261-265 266-270 271-275 276-280 281-285 286-290 291-295 296-300
301-305 306-310 311-315 316-320 321-325 326-330 331-335 336-340 341-345 346-350
351-355 356-360 361-365 366-370 371-375 376-380 381-385 386-390 391-395 396-400
401-405 406-410 411-415 416-420 421-425 426-430 431-435 436-440 441-445 446-450
451-455 456-460 461-465 466-470 471-475 476-480 481-485 486-490 491-495 496-500
501-505 506-510 511-515 516-520 521-525 526-530 531-535 536-540 541-545 546-550
551-555 556-560 561-565 566-570 571-575 576-580 581-585 586-590 591-595 596-600
601-605 606-610 611-615 616-620 621-625 626-630 631-635 636-640 641-645 646-650
651-655 656-660 661-665 666-670 671-675 676-680 681-685 686-690 691-695 696-700
701-705 706-710 711-715 716-720 721-725 726-730 731-733


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/2 200
last-modified Fri, 17 Jul 2026 15:09:26 GMT
content-type text/html; charset=utf-8
vary Cookie
vary Accept-Encoding
content-security-policy base-uri self ; object-src none ; script-src strict-dynamic unsafe-inline https: http: nonce-mapdbLQzgL8LesJJtqefIsX1rGhgEP unsafe-eval ; frame-ancestors self htt????/developers.google.com/_d/analytics-iframe; report-uri htt????/csp.withgoogle.com/csp/devsite/v2
strict-transport-security max-age=63072000; includeSubdomains; preload
x-xss-protection 0
x-content-type-options nosniff
cache-control no-cache, must-revalidate
expires 0
pragma no-cache
content-encoding gzip
x-cloud-trace-context d81756c32ef9c8f506c082cdc3de63fd
date Sun, 19 Jul 2026 13:10:25 GMT
server Google Frontend
content-length 60827
alt-svc h3= :443 ; ma=2592000,h3-29= :443 ; ma=2592000

Meta Tags

title="Protect resources with Cloud KMS keys  |  Compute Engine  |  Google Cloud Documentation"
name="google-signin-client-id" content="721724668570-nbkv1cfusk7kk4eni4pjvepaus73b13t.apps.googleusercontent.com"
name="google-signin-scope" content="profile email htt????/www.googleapis.com/auth/developerprofiles htt????/www.googleapis.com/auth/developerprofiles.award htt????/www.googleapis.com/auth/devprofiles.full_control.firstparty"
property="og:site_name" content="Google Cloud Documentation"
property="og:type" content="website"
name="theme-color" content="#1a73e8"
charset="utf-8"
content="IE=Edge" http-equiv="X-UA-Compatible"
name="viewport" content="width=device-width, initial-scale=1"
property="og:title" content="Protect resources with Cloud KMS keys  |  Compute Engine  |  Google Cloud Documentation"
property="og:url" content="htt????/docs.cloud.google.com/compute/docs/disks/customer-managed-encryption"
property="og:image" content="htt????/docs.cloud.google.com/_static/cloud/images/social-icon-google-cloud-1200-630.png"
property="og:image:width" content="1200"
property="og:image:height" content="630"
property="og:locale" content="en"
name="twitter:card" content="summary_large_image"

Load Info

page size421989
load time (s)0.419012
redirect count0
speed download145171
server IP 142.251.39.206
* all occurrences of the string "http://" have been changed to "htt???/"