Class: Google::Apis::CloudkmsV1::ImportJob
- Inherits:
-
Object
- Object
- Google::Apis::CloudkmsV1::ImportJob
- Includes:
- Google::Apis::Core::Hashable, Google::Apis::Core::JsonObjectSupport
- Defined in:
- lib/google/apis/cloudkms_v1/classes.rb,
lib/google/apis/cloudkms_v1/representations.rb,
lib/google/apis/cloudkms_v1/representations.rb
Overview
An ImportJob can be used to create CryptoKeys and CryptoKeyVersions using pre- existing key material, generated outside of Cloud KMS. When an ImportJob is created, Cloud KMS will generate a "wrapping key", which is a public/private key pair. You use the wrapping key to encrypt (also known as wrap) the pre- existing key material to protect it during the import process. The nature of the wrapping key depends on the choice of import_method. When the wrapping key generation is complete, the state will be set to ACTIVE and the public_key can be fetched. The fetched public key can then be used to wrap your pre-existing key material. Once the key material is wrapped, it can be imported into a new CryptoKeyVersion in an existing CryptoKey by calling ImportCryptoKeyVersion. Multiple CryptoKeyVersions can be imported with a single ImportJob. Cloud KMS uses the private key portion of the wrapping key to unwrap the key material. Only Cloud KMS has access to the private key. An ImportJob expires 3 days after it is created. Once expired, Cloud KMS will no longer be able to import or unwrap any key material that was wrapped with the ImportJob's public key. For more information, see Importing a key.
Instance Attribute Summary collapse
-
#attestation ⇒ Google::Apis::CloudkmsV1::KeyOperationAttestation
Contains an HSM-generated attestation about a key operation.
-
#create_time ⇒ String
Output only.
-
#crypto_key_backend ⇒ String
Immutable.
-
#expire_event_time ⇒ String
Output only.
-
#expire_time ⇒ String
Output only.
-
#generate_time ⇒ String
Output only.
-
#import_method ⇒ String
Required.
-
#name ⇒ String
Output only.
-
#protection_level ⇒ String
Required.
-
#public_key ⇒ Google::Apis::CloudkmsV1::WrappingPublicKey
The public key component of the wrapping key.
-
#public_key_format ⇒ String
Output only.
-
#state ⇒ String
Output only.
Instance Method Summary collapse
-
#initialize(**args) ⇒ ImportJob
constructor
A new instance of ImportJob.
-
#update!(**args) ⇒ Object
Update properties of this object.
Constructor Details
#initialize(**args) ⇒ ImportJob
Returns a new instance of ImportJob.
1972 1973 1974 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1972 def initialize(**args) update!(**args) end |
Instance Attribute Details
#attestation ⇒ Google::Apis::CloudkmsV1::KeyOperationAttestation
Contains an HSM-generated attestation about a key operation. For more
information, see Verifying attestations.
Corresponds to the JSON property attestation
1904 1905 1906 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1904 def attestation @attestation end |
#create_time ⇒ String
Output only. The time at which this ImportJob was created.
Corresponds to the JSON property createTime
1909 1910 1911 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1909 def create_time @create_time end |
#crypto_key_backend ⇒ String
Immutable. The resource name of the backend environment where the key material
for the wrapping key resides and where all related cryptographic operations
are performed. Currently, this field is only populated for keys stored in
HSM_SINGLE_TENANT. Note, this list is non-exhaustive and may apply to
additional ProtectionLevels in the future. Supported resources: * "projects/*/
locations/*/singleTenantHsmInstances/*"
Corresponds to the JSON property cryptoKeyBackend
1919 1920 1921 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1919 def crypto_key_backend @crypto_key_backend end |
#expire_event_time ⇒ String
Output only. The time this ImportJob expired. Only present if state is EXPIRED.
Corresponds to the JSON property expireEventTime
1924 1925 1926 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1924 def expire_event_time @expire_event_time end |
#expire_time ⇒ String
Output only. The time at which this ImportJob is scheduled for expiration and
can no longer be used to import key material.
Corresponds to the JSON property expireTime
1930 1931 1932 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1930 def expire_time @expire_time end |
#generate_time ⇒ String
Output only. The time this ImportJob's key material was generated.
Corresponds to the JSON property generateTime
1935 1936 1937 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1935 def generate_time @generate_time end |
#import_method ⇒ String
Required. Immutable. The wrapping method to be used for incoming key material.
Corresponds to the JSON property importMethod
1940 1941 1942 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1940 def import_method @import_method end |
#name ⇒ String
Output only. The resource name for this ImportJob in the format projects/*/
locations/*/keyRings/*/importJobs/*.
Corresponds to the JSON property name
1946 1947 1948 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1946 def name @name end |
#protection_level ⇒ String
Required. Immutable. The protection level of the ImportJob. This must match
the protection_level of the version_template on the CryptoKey you attempt to
import into.
Corresponds to the JSON property protectionLevel
1953 1954 1955 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1953 def protection_level @protection_level end |
#public_key ⇒ Google::Apis::CloudkmsV1::WrappingPublicKey
The public key component of the wrapping key. For details of the type of key
this public key corresponds to, see the ImportMethod.
Corresponds to the JSON property publicKey
1959 1960 1961 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1959 def public_key @public_key end |
#public_key_format ⇒ String
Output only. Specifies the WrappingPublicKey format provided by the customer
in the KeyManagementService.GetImportJob request.
Corresponds to the JSON property publicKeyFormat
1965 1966 1967 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1965 def public_key_format @public_key_format end |
#state ⇒ String
Output only. The current state of the ImportJob, indicating if it can be used.
Corresponds to the JSON property state
1970 1971 1972 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1970 def state @state end |
Instance Method Details
#update!(**args) ⇒ Object
Update properties of this object
1977 1978 1979 1980 1981 1982 1983 1984 1985 1986 1987 1988 1989 1990 |
# File 'lib/google/apis/cloudkms_v1/classes.rb', line 1977 def update!(**args) @attestation = args[:attestation] if args.key?(:attestation) @create_time = args[:create_time] if args.key?(:create_time) @crypto_key_backend = args[:crypto_key_backend] if args.key?(:crypto_key_backend) @expire_event_time = args[:expire_event_time] if args.key?(:expire_event_time) @expire_time = args[:expire_time] if args.key?(:expire_time) @generate_time = args[:generate_time] if args.key?(:generate_time) @import_method = args[:import_method] if args.key?(:import_method) @name = args[:name] if args.key?(:name) @protection_level = args[:protection_level] if args.key?(:protection_level) @public_key = args[:public_key] if args.key?(:public_key) @public_key_format = args[:public_key_format] if args.key?(:public_key_format) @state = args[:state] if args.key?(:state) end |