If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: docs.cloud.google.com/compute/docs/disks/customer-managed-encryption - Protect resources with Cloud K.

site address: docs.cloud.google.com/compute/docs/disks/customer-managed-encryption

site title: Protect resources with Cloud KMS keys     Compute Engine     Google Cloud Documentation

Our opinion (on Monday 20 July 2026 1:50:58 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:


page from cache: 12 hours ago
Meta tags:

Headings (most frequently used words):

gcloud, rest, cmek, console, disk, with, key, snapshot, and, or, create, from, encrypted, the, resources, on, for, required, permissions, cloud, kms, encrypt, new, vm, remove, revocation, protect, keys, stay, organized, collections, save, categorize, content, based, your, preferences, before, you, begin, encryption, specifications, limitations, manual, automated, creation, persistent, hyperdisk, balanced, in, confidential, mode, an, imported, image, attaching, boot, to, rotate, change, disable, destroy, what, next, roles, manually, ring, impact, of, configure, shutdown, products, pricing, support, engage, this, task,

Text of the page (most frequently used words):
the (691), disk (239), create (228), key (226), and (164), for (149), cloud (143), compute (140), you (134), #snapshot (131), with (122), vms (108), that (97), disks (97), kms (89), use (85), google (75), region (72), projects (70), name (68), zone (64), about (63), new (62), troubleshoot (62), snapshots (61), instance (59), from (57), using (57), encrypted (54), gcloud (51), can (51), image (50), encryption (49), manage (47), project (46), encrypt (45), type (43), cmek (43), your (43), engine (43), following (41), hyperdisk (40), server (39), view (38), images (37), keys (37), configure (36), key_ring (36), zones (35), project_id (35), source (35), storage (35), set (34), resources (33), windows (33), mig (33), post (32), overview (32), change (31), performance (31), locations (30), kms_project_id (30), global (29), managed (29), instances (29), disk_name (29), machine (29), location (28), reservation (27), snapshot_name (26), where (26), this (25), com (25), creation (25), persistent (24), request (24), keyrings (24), cryptokeys (24), https (23), googleapis (23), default (23), when (23), located (23), scoped (23), specify (22), replace (22), regional (22), network (21), method (21), console (21), service (21), sql (21), example (20), management (20), access (20), monitor (20), standard (19), attached (19), used (19), update (19), boot (18), want (18), rest (18), kmskeyname (18), linux (18), custom (18), confidential (18), gpu (18), are (17), command (17), shutdown (17), creating (17), enable (17), policies (16), mode (16), configuration (16), data (16), apply (16), remove (16), reservations (16), see (15), more (15), revocation (15), select (15), rotate (15), virtual (15), groups (15), ssh (15), recommendations (15), down (14), information (14), insert (14), sole (14), agent (14), regions (14), updatekmskey (14), optional (14), ring (14), contains (14), workload (14), host (14), load (14), connect (14), stop (13), include (13), protect (13), regionally (13), delete (13), balanced (13), bulk (13), microsoft (13), cluster (13), permissions (12), resource (12), workloads (12), volumes (12), add (12), choose (12), availability (12), best (12), must (11), customer (11), cli (11), property (11), uses (11), running (11), version (11), flag (11), click (11), existing (11), import (11), settings (11), types (11), roles (11), based (11), practices (11), stateful (11), debian (10), required (10), security (10), zonal (10), diskencryptionkey (10), customized (10), manually (10), time (10), instant (10), multiple (10), install (10), metadata (10), migs (10), machines (10), migrate (10), logs (10), all (9), page (9), template (9), created (9), templates (9), networking (9), disable (9), same (9), new_key_name (9), only (9), multi (9), tpu (9), h4d (9), application (9), licenses (9), tenant (9), openshift (9), start (9), hpc (9), samples (8), license (8), properties (8), construct (8), policy (8), includes (8), note (8), during (8), owned (8), different (8), one (8), operation (8), key_project_id (8), disk_type (8), snapshot_type (8), source_disk_name (8), backup (8), source_image (8), role (8), authentication (8), run (8), cpu (8), login (8), optimize (8), internal (8), disaster (8), recovery (8), high (8), guest (8), flexibility (8), dns (8), optimized (8), thumb (7), other (7), send (7), sourceimage (7), section (7), tenancy (7), automatically (7), then (7), such (7), encrypting (7), instead (7), migration (7), get (7), operations (7), globally (7), predefined (7), source_zone (7), services (7), demand (7), across (7), local (7), usage (7), commitments (7), startup (7), balancing (7), benchmark (7), idle (7), addresses (7), scale (7), deploy (7), back (7), mysql (7), maintenance (7), events (6), code (6), understand (6), need (6), under (6), details (6), after (6), configured (6), true (6), revoked (6), not (6), have (6), between (6), iam (6), copy (6), process (6), api (6), preview (6), operating (6), don (6), number (6), ssd (6), parameter (6), snapshot_scope_region (6), storage_location (6), snapshot_key (6), key_region (6), owns (6), hsm (6), accounts (6), errors (6), identity (6), apis (6), options (6), updates (6), files (6), nested (6), gpus (6), applications (6), group (6), pools (6), failover (6), extension (6), transfer (6), spot (6), action (5), system (5), shut (5), attach (5), external (5), will (5), machine_type (5), prevent (5), also (5), perform (5), archive (5), runs (5), list (5), sourcesnapshot (5), source_region (5), image_name (5), file (5), override (5), make (5), environment (5), how (5), monitoring (5), databases (5), future (5), drivers (5), virtualization (5), nvidia (5), placement (5), node (5), highly (5), available (5), build (5), modify (5), capacity (5), schedules (5), audit (5), symphony (5), email (5), scripts (5), manager (5), systems (5), enhanced (5), capabilities (5), restore (5), control (5), workstation (5), faq (5), flex (5), português (4), español (4), sign (4), support (4), machinetype (4), initializeparams (4), keyrevocationactiontype (4), menu (4), vm_name (4), within (4), destroy (4), automatic (4), which (4), these (4), rotation (4), beta (4), full (4), either (4), yyyyyyyyyyyyy (4), yyyyyyyy (4), schedule (4), device (4), disktypes (4), supports (4), storagelocations (4), source_project_id (4), destination_project_id (4), bullseye (4), v20231115 (4), size (4), autokey (4), manual (4), online (4), generation (4), infrastructure (4), cmeks (4), has (4), documentation (4), grant (4), account (4), permission (4), development (4), authenticate (4), provider (4), plan (4), through (4), tools (4), distributed (4), issues (4), ubuntu (4), bandwidth (4), tcp (4), pmu (4), share (4), upgrade (4), live (4), autoscaling (4), cross (4), requests (4), calendar (4), single (4), metrics (4), health (4), active (4), clusters (4), containers (4), container (4), database (4), postgresql (4), extensions (4), work (4), suspend (4), resize (4), graceful (4), plans (4), replication (4), review (4), bound (4), terms (3), status (3), content (3), its (3), apache (3), networks (3), define (3), expand (3), begin (3), alternatively (3), machinetypes (3), restart (3), helps (3), revoke (3), setting (3), enabled (3), shuts (3), disabling (3), effects (3), any (3), was (3), follow (3), steps (3), help (3), provide (3), protecting (3), dek (3), doesn (3), versions (3), value (3), format (3), directory (3), reference (3), continue (3), specified (3), snapshot_project_id (3), enter (3), imported (3), because (3), store (3), sourcedisk (3), snapshottype (3), snapshotencryptionkey (3), alternative (3), event (3), unless (3), enableconfidentialcompute (3), provisioned (3), throughput (3), provisioning (3), cloning (3), clones (3), first (3), decrease (3), latency (3), failure (3), user (3), project_number (3), credentials (3), guides (3), observability (3), analytics (3), troubleshooting (3), pro (3), serial (3), configurations (3), patterns (3), higher (3), discounts (3), cuds (3), scalable (3), resilient (3), autoscale (3), balancer (3), testing (3), ibm (3), spectrum (3), deploying (3), prepare (3), deployment (3), rhel (3), certificates (3), query (3), state (3), increase (3), lifecycle (3), design (3), non (3), pool (3), move (3), workstations (3), series (3), tpus (3), product (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), third (2), site (2), youtube (2), center (2), started (2), pricing (2), products (2), last (2), updated (2), 2026 (2), utc (2), otherwise (2), licensed (2), feedback (2), learn (2), next (2), instancetemplates (2), networkinterfaces (2), family (2), body (2), fields (2), open (2), protected (2), public (2), hours (2), deleting (2), reverse (2), preceding (2), impact (2), still (2), until (2), decrypt (2), contents (2), encrypts (2), requirements (2), without (2), response (2), represents (2), progress (2), operation_name (2), reduce (2), methods (2), resizing (2), form (2), disk_alias (2), shown (2), supplied (2), imageencryptionkey (2), compressed (2), source_disk (2), drop (2), before (2), recommends (2), features (2), createsnapshot (2), stored (2), allowed (2), defined (2), choice (2), volume (2), indicate (2), fails (2), able (2), accidental (2), deletion (2), task (2), similarly (2), computing (2), iops (2), assign (2), replica (2), rings (2), provision (2), they (2), deleted (2), bare (2), metal (2), offline (2), were (2), spread (2), west1 (2), own (2), limitations (2), additional (2), specifications (2), related (2), administrator (2), might (2), ensure (2), cloudkms (2), cryptokeyencrypterdecrypter (2), gserviceaccount (2), already (2), idp (2), federated (2), supported (2), owner (2), serviceusage (2), sdk (2), languages (2), frameworks (2), costs (2), industry (2), solutions (2), hybrid (2), multicloud (2), pipelines (2), hosting (2), quota (2), commitment (2), consumption (2), registration (2), sles (2), export (2), port (2), collecting (2), nodes (2), report (2), arm (2), core (2), rdp (2), general (2), app (2), analyze (2), visible (2), cores (2), committed (2), underutilized (2), insights (2), utilization (2), web (2), autohealing (2), iis (2), shared (2), reserve (2), autoscaler (2), autoscalers (2), activity (2), kubernetes (2), place (2), redis (2), writer (2), always (2), alwayson (2), synchronization (2), switch (2), byol (2), payg (2), byos (2), changes (2), families (2), guide (2), securing (2), simulate (2), topology (2), together (2), repairs (2), repair (2), check (2), failures (2), suspended (2), stopped (2), target (2), distribution (2), physical (2), cancel (2), once (2), limit (2), interfaces (2), ipv6 (2), static (2), basic (2), consistent (2), appliances (2), asynchronous (2), names (2), mount (2), memory (2), extreme (2), organization (2), advanced (2), rdma (2), specific (2), preemptible (2), models (2), rtx (2), vws (2), constraints (2), accelerator (2), technology (2), areas (2), close (2), subscribe, newsletter, our, decade, climate, join, cookies, privacy, tech, twitter, blog, engage, training, certification, architecture, getting, github, release, notes, community, forums, contact, sales, marketplace, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, sample, incorrectinformationorsamplecode, missing, missingtheinformationsamplesineed, otherdown, tell, except, noted, java, registered, trademark, oracle, affiliates, developers, creative, commons, attribution, what, accessconfigs, one_to_one_nat, read_write, explicitly, minimal, looks, like, instance_template_name, image_project, machine_type_zone, creates, again, does, helping, enabling, cannot, protects, affected, follows, accessible, trigger, there, delay, hour, usable, decrypting, may, order, destroying, quickly, longer, removing, referred, revoking, currently, primary, containing, new_kms_key, changing, meet, compliance, downtime, rotating, previous, succeeded, 100, poll, determine, call, successful, making, item, patch, potential, consequences, being, compromised, recommend, regular, unique, alias, mounting, chooses, assigned, field, applicable, dev, devicename, yes, attaching, partial, url, reside, rawdisk, http, tar, sourcetype, raw, uri, upload, compress, try, won, original, capture, clean, failsafe, unsuccessful, caution, incremental, well, convert, completely, n2d, isn, standalone, replicas, two, specifying, supplying, described, simplifies, managing, automating, assignment, ahead, generated, part, automated, a4x, c4a, c4d, fourth, second, unsupported, recommended, approach, prevents, cases, depend, domains, geographical, terminated, ensures, isolation, increases, reliability, working, them, hardware, backed, enclaves, aes, 256, itself, give, exact, necessary, ask, granting, folders, organizations, correct, principal, result, important, cryptokey, encrypter, decrypter, even, binding, member, serviceaccount, haven, verifies, selecting, installed, previously, sure, latest, components, init, installation, initialize, tab, case, reviewing, relevant, likely, admin, serviceusageadmin, decide, whether, going, ids, numbers, identifying, document, provides, known, save, categorize, preferences, stay, organized, collections, home, concurrent, renewal, nvme, common, pay, viewing, output, diagnostic, sudoers, screenshots, generate, bug, blackwell, soft, lockups, bus, locks, rescue, inaccessible, dumps, kernel, panic, fstab, unresponsive, suspension, reboots, shutdowns, connectivity, tips, nics, dpdk, improve, resiliency, communication, compact, idpf, interface, irdma, driver, nic, customize, threads, per, sustained, merge, split, extend, renew, purchase, cost, savings, dynamic, overcommit, cpus, floating, reliable, udp, backends, routing, scaling, consuming, consume, combine, cud, allow, sharing, decisions, signals, serving, predictions, organize, labels, states, observe, reports, tensorflow, inference, tensorrt5, learning, monte, carlo, spark, forwarding, others, integrate, clustering, exchange, 2016, sharepoint, strategies, passive, inactive, setups, built, integrations, validation, deployed, transition, test, hammerdb, bucket, aws, ec2, pacemaker, s2d, block, netapp, hot, standby, drbd, architectures, client, private, address, mailjet, mailgun, sendgrid, sending, blue, green, deployments, lamp, joomla, asp, net, interactive, mongodb, flask, terraform, servers, over, mtls, random, generator, virtio, rng, accurate, protocol, ntp, append, els, restrictions, packages, deprecate, trusted, red, hat, knowledgebase, functionality, risks, vpc, controls, kek, secure, expiration, shielded, attributes, handle, notices, faulty, unmanaged, affect, preserved, turn, off, alternate, repairing, maintain, upgrades, selectively, applying, accelerate, out, outage, rebalance, reenable, proactive, redistribution, shape, distribute, info, edit, rename, reset, resume, referrers, uuid, recover, corrupted, duplicate, alerts, backups, vss, protection, considerations, synchronous, consistency, failback, replicate, limits, evaluate, symbolic, links, practice, ram, exapools, verify, ptr, record, rates, tags, restrict, automate, password, require, powershell, sac, securely, apps, root, vpn, bastion, iap, connection, browser, connections, iso, prerequisites, importing, exporting, bring, path, detach, reattach, constraint, accounting, examples, slurm, reserved, team, slice, slices, adds, scenarios, deterministic, base, ready, aci, preempted, historical, similar, displays, ops, logging, subnet, gpudirect, ultra, minimum, platform, hostname, quickstarts, office, licensing, premium, strategy, gemini, accelerators, platforms, scores, purpose, discover, free, skip, main,


Text of the page (random words):
y permissions to protect resources by using cloud kms keys ask your administrator to grant the cloud kms cryptokey encrypter decrypter roles cloudkms cryptokeyencrypterdecrypter iam role to the compute engine service agent on your project important you must grant this role to the compute engine service agent not to your user account failure to grant the role to the correct principal might result in permission errors for more information about granting roles see manage access to projects folders and organizations this predefined role contains the permissions required to protect resources by using cloud kms keys to see the exact permissions that are required expand the required permissions section required permissions the following permissions are required to protect resources by using cloud kms keys to rotate an encryption key protecting a disk compute disks updatekmskey to rotate an encryption key protecting a snapshot compute snapshots updatekmskey your administrator might also be able to give the compute engine service agent these permissions with custom roles or other predefined roles encryption specifications the cloud kms keys used to help protect your data in compute engine are aes 256 keys these keys are key encryption keys and they encrypt the data encryption keys that encrypt your data not the data itself the data on the disks is encrypted using google owned and google managed encryption keys for specifications related to the default encryption in google cloud see default encryption at rest in the security documentation with confidential mode for hyperdisk balanced and cloud hsm the data encryption key dek has additional security properties with hardware backed enclaves limitations you can t encrypt existing resources with cmeks you can only encrypt disks images and snapshots with cmeks when you create them when you create a disk from a cmek encrypted instant snapshot you must specify the key used to encrypt the source disk you don t have to specify the key when working with other cmek encrypted resources such as disk clones and standard snapshots when you create a regionally scoped snapshot preview from a disk encrypted with a cmek you must create the snapshot with a regional cmek that s in the same location as the snapshot this ensures regional isolation of your snapshot and increases your snapshot s reliability you can t use your own keys with local ssd disks because the keys are managed by google cloud infrastructure and deleted when the vm is terminated regional resources disks can only be encrypted by a key in one of the following cloud kms locations a key in the same region as the disk a multi regional key in the same geographical location as the disk a key in the global location for example a disk in zone us west1 a can be encrypted by a key in the global location the us west1 region or the us multi region global resources such as images and snapshots can be encrypted by keys in any location for more information see types of locations for cloud kms note we recommended using keys in the same location as the resources you want to protect this approach helps to decrease latency and prevents cases where resources depend on services spread across multiple failure domains you can t change or remove the encryption key for an image or instant snapshot you can t remove a disk or snapshot s encryption key or change the key from a cmek to a google owned and managed key instead create a copy of the disk or snapshot and specify a new encryption type for the copy for more information see remove the cmek from a disk and remove the cmek from a snapshot you can t rotate or change the cmek of online confidential hyperdisk volumes or online hyperdisk volumes that are attached to unsupported machine types you can rotate or change the cmek on only the following disk types all persistent disk volumes hyperdisk volumes that were created from an instant snapshot offline hyperdisk volumes offline confidential hyperdisk volumes online hyperdisk volumes that are attached to first or second generation machine types online hyperdisk volumes that are attached to the following third or fourth generation machine types a3 a4 z3 h4d all tpu versions bare metal a4x c4 c4a c4d c3 and x4 machine types you can t change the key for hyperdisk volumes that you created by cloning a disk unless you have deleted the source disk and all other clones of the source disk manual or automated key creation you can either create cloud kms keys manually or use cloud kms autokey autokey simplifies creating and managing cloud kms keys by automating provisioning and assignment with autokey you don t need to provision key rings keys and service accounts ahead of time instead they are generated on demand as part of compute engine resource creation for more information see the autokey overview manually create key ring and key for the google cloud project that runs cloud kms create a key ring and a key as described in creating key rings and keys encrypt a new persistent disk with cmek you can encrypt a new persistent disk by supplying a key during vm or disk creation console in the google cloud console go to the disks page go to disks click create disk and enter the properties for the new disk under encryption select customer managed key in the drop down menu select the cloud kms key that you want to use to encrypt this disk to create the disk click create gcloud create an encrypted disk by using the gcloud compute disks create command and specify the key using the kms key flag gcloud compute disks create disk_name kms key projects kms_project_id locations region keyrings key_ring cryptokeys key replace the following disk_name the name of the new disk kms_project_id the project that owns the cloud kms key region the region where the key is located key_ring the name of the key ring that includes the key key the name of the key used to encrypt the disk note if you re creating a regional persistent disk you must assign the disk replicas to two different zones by specifying the replica zones flag rest construct a post request to the instances insert method to encrypt a disk use the diskencryptionkey property with the kmskeyname property for example you can encrypt a new disk during vm creation with your cloud kms key by using the following post https compute googleapis com compute v1 projects project_id zones zone instances machinetype zones zone machinetypes machine_type disks type persistent diskencryptionkey kmskeyname projects kms_project_id locations region keyrings key_ring cryptokeys key initializeparams sourceimage source_image boot true replace the following project_id the id of the google cloud project running compute engine zone the zone to create the vm in machine_type the machine type for example c3 standard 4 kms_project_id the project that owns the cloud kms key region the region where the disk is located key_ring the name of the key ring that includes the key key the name of the key used to encrypt the disk source_image the image to use when creating the vm for example projects debian cloud global images debian 11 bullseye v20231115 similarly you can use the disks insert method to create a new standalone persistent disk and encrypt it with your cloud kms key post https compute googleapis com compute v1 projects project_id zones zone disks sourceimage source_image name disk_name diskencryptionkey kmskeyname projects kms_project_id locations region keyrings key_ring cryptokeys key type projects project_id zones zone disktypes disk_type replace the following project_id the id of the google cloud project running compute engine zone the zone to create the disk in source_image the image to use when creating the disk for example projects debian cloud global images debian 11 bullseye v20231115 disk_name a name for the new disk kms_project_id the project that owns the cloud kms key region the region where the disk is located key_ring the name of the key ring that includes the key key the name of the key used to encrypt the disk disk_type the type of disk to create create a hyperdisk balanced disk in confidential mode you can create a new hyperdisk balanced disk in confidential mode with the google cloud console google cloud cli or rest to create a disk that isn t in confidential mode follow the steps in create a persistent disk from a snapshot encrypted with cmek console in the google cloud console go to the disks page go to disks click create disk and enter the properties for the new disk in the disk settings section choose hyperdisk balanced for the disk type optional change the default disk size provisioned iops and provisioned throughput settings for the disk in the encryption section select cloud kms key in the list of keys select the cloud hsm key that you want to use to encrypt this disk in the confidential computing section select enable confidential computing services to create the disk click create gcloud encrypt a new disk with confidential mode for hyperdisk balanced by using the gcloud compute disks create command enable confidential mode with the confidential compute flag and specify the key using the kms key flag gcloud compute disks create disk_name type hyperdisk balanced kms key projects kms_project_id locations region keyrings key_ring cryptokeys key confidential compute replace the following disk_name the name of the new disk kms_project_id the project that owns the cloud hsm key region the region where the key is located key_ring the name of the key ring that includes the key key the name of the key used to encrypt the disk rest construct a post request to the instances insert method to encrypt a disk with confidential mode for hyperdisk balanced use the diskencryptionkey property with the kmskeyname property and set the enableconfidentialcompute flag for example you can encrypt a new disk during vm creation with your cloud hsm key by using the following post https compute googleapis com compute v1 projects project_id zones zone instances machinetype zones zone machinetypes machine_type disks type disk_type diskencryptionkey kmskeyname projects kms_project_id locations region keyrings key_ring cryptokeys key initializeparams sourceimage source_image enableconfidentialcompute true boot true networkinterfaces network global networks default replace the following disk_type the type of disk to create for example hyperdisk balanced project_id the id of the google cloud project running compute engine zone the zone to create the vm in machine_type the machine type for example n2d standard 4 kms_project_id the project that owns the cloud hsm key region the region where the disk is located key_ring the name of the key ring that includes the key key the name of the key used to encrypt the disk source_image the image that supports confidential vm to use when creating the vm for example projects debian cloud global images debian 11 bullseye v20231115 similarly you can use the disks insert method to create a new confidential mode for hyperdisk balanced post https compute googleapis com compute v1 projects project_id zones zone disks sourceimage source_image name disk_name diskencryptionkey kmskeyname projects kms_project_id locations region keyrings key_ring cryptokeys key type projects project_id zones zone disktypes disk_type enableconfidentialcompute true replace the following project_id the id of the google cloud project running compute engine zone the zone to create the disk in source_image the image that supports confidential vm when creating the disk for example projects debian cloud global images debian 11 bullseye v20231115 disk_name a name for the new disk kms_project_id the project that owns the cloud hsm key region the region where the disk is located key_ring the name of the key ring that includes the key key the name of the key used to encrypt the disk disk_type the type of disk to create for example hyperdisk balanced create a snapshot from a disk encrypted with a cmek to create a snapshot from a disk that is encrypted with cmek you must create the snapshot with the same encryption key that you used to encrypt the disk you can t create a snapshot that uses a cmek unless the source disk uses cmek as well also you can t convert cmek encrypted disks or snapshots to use google cloud default encryption unless you create a completely new disk image and a new persistent disk snapshots from disks encrypted with cmek are incremental permissions required for this task to perform this task you must have the following permissions compute snapshots create on the project compute disks createsnapshot caution if you try to create a snapshot from a disk and the snapshot creation process fails you won t be able to delete the original disk until you capture a clean snapshot this failsafe helps to prevent the accidental deletion of source data in the event of an unsuccessful backup console in the google cloud console go to the snapshots page go to snapshots click create snapshot under source disk choose the source disk for the snapshot the snapshot is automatically encrypted with the same key used by the source disk gcloud for customer managed encryption the cloud kms key that was used to encrypt the disk is also used to encrypt the snapshot you can create your snapshot in the storage location policy defined by your snapshot settings or using an alternative storage location of your choice for more information see choose your snapshot storage location to create a snapshot in the predefined or customized default location configured in your snapshot settings use the gcloud compute snapshots create command gcloud compute snapshots create snapshot_name source disk zone source_zone source disk source_disk_name snapshot type snapshot_type alternatively to override the snapshot settings and create a snapshot in a custom storage location include the storage location flag to indicate where to store your snapshot gcloud compute snapshots create snapshot_name source disk zone source_zone source disk source_disk_name snapshot type snapshot_type storage location storage_location preview to create a regionally scoped snapshot in an allowed region include the region flag to indicate where to create your snapshot gcloud beta compute snapshots create snapshot_name region snapshot_scope_region source disk source_disk_name source disk zone source_zone snapshot type snapshot_type kms key projects kms_project_id locations key_region keyrings key_ring cryptokeys snapshot_key replace the following snapshot_name a name for the snapshot source_zone the zone of the source disk source_disk_name the name of the disk volume from which you want to create a snapshot kms_project_id the project that contains the encryption key that is stored in cloud key management service key_region the region where the cloud kms key is located key_ring the name of the key ring that contains the cloud kms key snapshot_key the name of the cloud kms key that you used to encrypt the source disk snap...
Images from subpage: "docs.cloud.google.com/compute/docs/instances/custom-hostname... " Verify
Images from subpage: "docs.cloud.google.com/compute/docs/instances/creating-instan... " Verify
Images from subpage: "docs.cloud.google.com/compute/docs/instances/specify-min-cpu... " Verify
Images from subpage: "docs.cloud.google.com/compute/docs/gpus/about-gpus" Verify
Images from subpage: "docs.cloud.google.com/compute/docs/gpus/create-vm-with-gpus... " Verify

Verified site has: 733 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
201-205 206-210 211-215 216-220 221-225 226-230 231-235 236-240 241-245 246-250
251-255 256-260 261-265 266-270 271-275 276-280 281-285 286-290 291-295 296-300
301-305 306-310 311-315 316-320 321-325 326-330 331-335 336-340 341-345 346-350
351-355 356-360 361-365 366-370 371-375 376-380 381-385 386-390 391-395 396-400
401-405 406-410 411-415 416-420 421-425 426-430 431-435 436-440 441-445 446-450
451-455 456-460 461-465 466-470 471-475 476-480 481-485 486-490 491-495 496-500
501-505 506-510 511-515 516-520 521-525 526-530 531-535 536-540 541-545 546-550
551-555 556-560 561-565 566-570 571-575 576-580 581-585 586-590 591-595 596-600
601-605 606-610 611-615 616-620 621-625 626-630 631-635 636-640 641-645 646-650
651-655 656-660 661-665 666-670 671-675 676-680 681-685 686-690 691-695 696-700
701-705 706-710 711-715 716-720 721-725 726-730 731-733


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/2 200
last-modified Fri, 17 Jul 2026 15:09:26 GMT
content-type text/html; charset=utf-8
vary Cookie
vary Accept-Encoding
content-security-policy base-uri self ; object-src none ; script-src strict-dynamic unsafe-inline https: http: nonce-mapdbLQzgL8LesJJtqefIsX1rGhgEP unsafe-eval ; frame-ancestors self htt????/developers.google.com/_d/analytics-iframe; report-uri htt????/csp.withgoogle.com/csp/devsite/v2
strict-transport-security max-age=63072000; includeSubdomains; preload
x-xss-protection 0
x-content-type-options nosniff
cache-control no-cache, must-revalidate
expires 0
pragma no-cache
content-encoding gzip
x-cloud-trace-context d81756c32ef9c8f506c082cdc3de63fd
date Sun, 19 Jul 2026 13:10:25 GMT
server Google Frontend
content-length 60827
alt-svc h3= :443 ; ma=2592000,h3-29= :443 ; ma=2592000

Meta Tags

title="Protect resources with Cloud KMS keys  |  Compute Engine  |  Google Cloud Documentation"
name="google-signin-client-id" content="721724668570-nbkv1cfusk7kk4eni4pjvepaus73b13t.apps.googleusercontent.com"
name="google-signin-scope" content="profile email htt????/www.googleapis.com/auth/developerprofiles htt????/www.googleapis.com/auth/developerprofiles.award htt????/www.googleapis.com/auth/devprofiles.full_control.firstparty"
property="og:site_name" content="Google Cloud Documentation"
property="og:type" content="website"
name="theme-color" content="#1a73e8"
charset="utf-8"
content="IE=Edge" http-equiv="X-UA-Compatible"
name="viewport" content="width=device-width, initial-scale=1"
property="og:title" content="Protect resources with Cloud KMS keys  |  Compute Engine  |  Google Cloud Documentation"
property="og:url" content="htt????/docs.cloud.google.com/compute/docs/disks/customer-managed-encryption"
property="og:image" content="htt????/docs.cloud.google.com/_static/cloud/images/social-icon-google-cloud-1200-630.png"
property="og:image:width" content="1200"
property="og:image:height" content="630"
property="og:locale" content="en"
name="twitter:card" content="summary_large_image"

Load Info

page size421989
load time (s)0.419012
redirect count0
speed download145171
server IP 142.251.39.206
* all occurrences of the string "http://" have been changed to "htt???/"