public static final class CmekSettings.Builder extends GeneratedMessageV3.Builder<CmekSettings.Builder> implements CmekSettingsOrBuilder
Describes the customer-managed encryption key (CMEK) settings associated with a project, folder, organization, billing account, or flexible resource. Note: CMEK for the Logs Router can currently only be configured for GCP organizations. Once configured, it applies to all projects and folders in the GCP organization. See Enabling CMEK for Logs Router for more information.
Protobuf type google.logging.v2.CmekSettings
Inheritance
Object > AbstractMessageLite.Builder<MessageType,BuilderType> > AbstractMessage.Builder<BuilderType> > GeneratedMessageV3.Builder > CmekSettings.BuilderImplements
CmekSettingsOrBuilderMethods
addRepeatedField(Descriptors.FieldDescriptor field, Object value)
public CmekSettings.Builder addRepeatedField(Descriptors.FieldDescriptor field, Object value)
Name | Description |
field | FieldDescriptor |
value | Object |
Type | Description |
CmekSettings.Builder |
build()
public CmekSettings build()
Type | Description |
CmekSettings |
buildPartial()
public CmekSettings buildPartial()
Type | Description |
CmekSettings |
clear()
public CmekSettings.Builder clear()
Type | Description |
CmekSettings.Builder |
clearField(Descriptors.FieldDescriptor field)
public CmekSettings.Builder clearField(Descriptors.FieldDescriptor field)
Name | Description |
field | FieldDescriptor |
Type | Description |
CmekSettings.Builder |
clearKmsKeyName()
public CmekSettings.Builder clearKmsKeyName()
The resource name for the configured Cloud KMS key.
KMS key name format:
"projects/[PROJECT_ID]/locations/[LOCATION]/keyRings/[KEYRING]/cryptoKeys/[KEY]"
For example:
"projects/my-project-id/locations/my-region/keyRings/key-ring-name/cryptoKeys/key-name"
To enable CMEK for the Logs Router, set this field to a valid
kms_key_name
for which the associated service account has the required
roles/cloudkms.cryptoKeyEncrypterDecrypter
role assigned for the key.
The Cloud KMS key used by the Log Router can be updated by changing the
kms_key_name
to a new valid key name. Encryption operations that are in
progress will be completed with the key that was in use when they started.
Decryption operations will be completed using the key that was used at the
time of encryption unless access to that key has been revoked.
To disable CMEK for the Logs Router, set this field to an empty string.
See Enabling CMEK for Logs
Router
for more information.
string kms_key_name = 2;
Type | Description |
CmekSettings.Builder | This builder for chaining. |
clearName()
public CmekSettings.Builder clearName()
Output only. The resource name of the CMEK settings.
string name = 1 [(.google.api.field_behavior) = OUTPUT_ONLY];
Type | Description |
CmekSettings.Builder | This builder for chaining. |
clearOneof(Descriptors.OneofDescriptor oneof)
public CmekSettings.Builder clearOneof(Descriptors.OneofDescriptor oneof)
Name | Description |
oneof | OneofDescriptor |
Type | Description |
CmekSettings.Builder |
clearServiceAccountId()
public CmekSettings.Builder clearServiceAccountId()
Output only. The service account that will be used by the Logs Router to access your
Cloud KMS key.
Before enabling CMEK for Logs Router, you must first assign the role
roles/cloudkms.cryptoKeyEncrypterDecrypter
to the service account that
the Logs Router will use to access your Cloud KMS key. Use
GetCmekSettings to
obtain the service account ID.
See Enabling CMEK for Logs
Router
for more information.
string service_account_id = 3 [(.google.api.field_behavior) = OUTPUT_ONLY];
Type | Description |
CmekSettings.Builder | This builder for chaining. |
clone()
public CmekSettings.Builder clone()
Type | Description |
CmekSettings.Builder |
getDefaultInstanceForType()
public CmekSettings getDefaultInstanceForType()
Type | Description |
CmekSettings |
getDescriptor()
public static final Descriptors.Descriptor getDescriptor()
Type | Description |
Descriptor |
getDescriptorForType()
public Descriptors.Descriptor getDescriptorForType()
Type | Description |
Descriptor |
getKmsKeyName()
public String getKmsKeyName()
The resource name for the configured Cloud KMS key.
KMS key name format:
"projects/[PROJECT_ID]/locations/[LOCATION]/keyRings/[KEYRING]/cryptoKeys/[KEY]"
For example:
"projects/my-project-id/locations/my-region/keyRings/key-ring-name/cryptoKeys/key-name"
To enable CMEK for the Logs Router, set this field to a valid
kms_key_name
for which the associated service account has the required
roles/cloudkms.cryptoKeyEncrypterDecrypter
role assigned for the key.
The Cloud KMS key used by the Log Router can be updated by changing the
kms_key_name
to a new valid key name. Encryption operations that are in
progress will be completed with the key that was in use when they started.
Decryption operations will be completed using the key that was used at the
time of encryption unless access to that key has been revoked.
To disable CMEK for the Logs Router, set this field to an empty string.
See Enabling CMEK for Logs
Router
for more information.
string kms_key_name = 2;
Type | Description |
String | The kmsKeyName. |
getKmsKeyNameBytes()
public ByteString getKmsKeyNameBytes()
The resource name for the configured Cloud KMS key.
KMS key name format:
"projects/[PROJECT_ID]/locations/[LOCATION]/keyRings/[KEYRING]/cryptoKeys/[KEY]"
For example:
"projects/my-project-id/locations/my-region/keyRings/key-ring-name/cryptoKeys/key-name"
To enable CMEK for the Logs Router, set this field to a valid
kms_key_name
for which the associated service account has the required
roles/cloudkms.cryptoKeyEncrypterDecrypter
role assigned for the key.
The Cloud KMS key used by the Log Router can be updated by changing the
kms_key_name
to a new valid key name. Encryption operations that are in
progress will be completed with the key that was in use when they started.
Decryption operations will be completed using the key that was used at the
time of encryption unless access to that key has been revoked.
To disable CMEK for the Logs Router, set this field to an empty string.
See Enabling CMEK for Logs
Router
for more information.
string kms_key_name = 2;
Type | Description |
ByteString | The bytes for kmsKeyName. |
getName()
public String getName()
Output only. The resource name of the CMEK settings.
string name = 1 [(.google.api.field_behavior) = OUTPUT_ONLY];
Type | Description |
String | The name. |
getNameBytes()
public ByteString getNameBytes()
Output only. The resource name of the CMEK settings.
string name = 1 [(.google.api.field_behavior) = OUTPUT_ONLY];
Type | Description |
ByteString | The bytes for name. |
getServiceAccountId()
public String getServiceAccountId()
Output only. The service account that will be used by the Logs Router to access your
Cloud KMS key.
Before enabling CMEK for Logs Router, you must first assign the role
roles/cloudkms.cryptoKeyEncrypterDecrypter
to the service account that
the Logs Router will use to access your Cloud KMS key. Use
GetCmekSettings to
obtain the service account ID.
See Enabling CMEK for Logs
Router
for more information.
string service_account_id = 3 [(.google.api.field_behavior) = OUTPUT_ONLY];
Type | Description |
String | The serviceAccountId. |
getServiceAccountIdBytes()
public ByteString getServiceAccountIdBytes()
Output only. The service account that will be used by the Logs Router to access your
Cloud KMS key.
Before enabling CMEK for Logs Router, you must first assign the role
roles/cloudkms.cryptoKeyEncrypterDecrypter
to the service account that
the Logs Router will use to access your Cloud KMS key. Use
GetCmekSettings to
obtain the service account ID.
See Enabling CMEK for Logs
Router
for more information.
string service_account_id = 3 [(.google.api.field_behavior) = OUTPUT_ONLY];
Type | Description |
ByteString | The bytes for serviceAccountId. |
internalGetFieldAccessorTable()
protected GeneratedMessageV3.FieldAccessorTable internalGetFieldAccessorTable()
Type | Description |
FieldAccessorTable |
isInitialized()
public final boolean isInitialized()
Type | Description |
boolean |
mergeFrom(CmekSettings other)
public CmekSettings.Builder mergeFrom(CmekSettings other)
Name | Description |
other | CmekSettings |
Type | Description |
CmekSettings.Builder |
mergeFrom(CodedInputStream input, ExtensionRegistryLite extensionRegistry)
public CmekSettings.Builder mergeFrom(CodedInputStream input, ExtensionRegistryLite extensionRegistry)
Name | Description |
input | CodedInputStream |
extensionRegistry | ExtensionRegistryLite |
Type | Description |
CmekSettings.Builder |
Type | Description |
IOException |
mergeFrom(Message other)
public CmekSettings.Builder mergeFrom(Message other)
Name | Description |
other | Message |
Type | Description |
CmekSettings.Builder |
mergeUnknownFields(UnknownFieldSet unknownFields)
public final CmekSettings.Builder mergeUnknownFields(UnknownFieldSet unknownFields)
Name | Description |
unknownFields | UnknownFieldSet |
Type | Description |
CmekSettings.Builder |
setField(Descriptors.FieldDescriptor field, Object value)
public CmekSettings.Builder setField(Descriptors.FieldDescriptor field, Object value)
Name | Description |
field | FieldDescriptor |
value | Object |
Type | Description |
CmekSettings.Builder |
setKmsKeyName(String value)
public CmekSettings.Builder setKmsKeyName(String value)
The resource name for the configured Cloud KMS key.
KMS key name format:
"projects/[PROJECT_ID]/locations/[LOCATION]/keyRings/[KEYRING]/cryptoKeys/[KEY]"
For example:
"projects/my-project-id/locations/my-region/keyRings/key-ring-name/cryptoKeys/key-name"
To enable CMEK for the Logs Router, set this field to a valid
kms_key_name
for which the associated service account has the required
roles/cloudkms.cryptoKeyEncrypterDecrypter
role assigned for the key.
The Cloud KMS key used by the Log Router can be updated by changing the
kms_key_name
to a new valid key name. Encryption operations that are in
progress will be completed with the key that was in use when they started.
Decryption operations will be completed using the key that was used at the
time of encryption unless access to that key has been revoked.
To disable CMEK for the Logs Router, set this field to an empty string.
See Enabling CMEK for Logs
Router
for more information.
string kms_key_name = 2;
Name | Description |
value | String The kmsKeyName to set. |
Type | Description |
CmekSettings.Builder | This builder for chaining. |
setKmsKeyNameBytes(ByteString value)
public CmekSettings.Builder setKmsKeyNameBytes(ByteString value)
The resource name for the configured Cloud KMS key.
KMS key name format:
"projects/[PROJECT_ID]/locations/[LOCATION]/keyRings/[KEYRING]/cryptoKeys/[KEY]"
For example:
"projects/my-project-id/locations/my-region/keyRings/key-ring-name/cryptoKeys/key-name"
To enable CMEK for the Logs Router, set this field to a valid
kms_key_name
for which the associated service account has the required
roles/cloudkms.cryptoKeyEncrypterDecrypter
role assigned for the key.
The Cloud KMS key used by the Log Router can be updated by changing the
kms_key_name
to a new valid key name. Encryption operations that are in
progress will be completed with the key that was in use when they started.
Decryption operations will be completed using the key that was used at the
time of encryption unless access to that key has been revoked.
To disable CMEK for the Logs Router, set this field to an empty string.
See Enabling CMEK for Logs
Router
for more information.
string kms_key_name = 2;
Name | Description |
value | ByteString The bytes for kmsKeyName to set. |
Type | Description |
CmekSettings.Builder | This builder for chaining. |
setName(String value)
public CmekSettings.Builder setName(String value)
Output only. The resource name of the CMEK settings.
string name = 1 [(.google.api.field_behavior) = OUTPUT_ONLY];
Name | Description |
value | String The name to set. |
Type | Description |
CmekSettings.Builder | This builder for chaining. |
setNameBytes(ByteString value)
public CmekSettings.Builder setNameBytes(ByteString value)
Output only. The resource name of the CMEK settings.
string name = 1 [(.google.api.field_behavior) = OUTPUT_ONLY];
Name | Description |
value | ByteString The bytes for name to set. |
Type | Description |
CmekSettings.Builder | This builder for chaining. |
setRepeatedField(Descriptors.FieldDescriptor field, int index, Object value)
public CmekSettings.Builder setRepeatedField(Descriptors.FieldDescriptor field, int index, Object value)
Name | Description |
field | FieldDescriptor |
index | int |
value | Object |
Type | Description |
CmekSettings.Builder |
setServiceAccountId(String value)
public CmekSettings.Builder setServiceAccountId(String value)
Output only. The service account that will be used by the Logs Router to access your
Cloud KMS key.
Before enabling CMEK for Logs Router, you must first assign the role
roles/cloudkms.cryptoKeyEncrypterDecrypter
to the service account that
the Logs Router will use to access your Cloud KMS key. Use
GetCmekSettings to
obtain the service account ID.
See Enabling CMEK for Logs
Router
for more information.
string service_account_id = 3 [(.google.api.field_behavior) = OUTPUT_ONLY];
Name | Description |
value | String The serviceAccountId to set. |
Type | Description |
CmekSettings.Builder | This builder for chaining. |
setServiceAccountIdBytes(ByteString value)
public CmekSettings.Builder setServiceAccountIdBytes(ByteString value)
Output only. The service account that will be used by the Logs Router to access your
Cloud KMS key.
Before enabling CMEK for Logs Router, you must first assign the role
roles/cloudkms.cryptoKeyEncrypterDecrypter
to the service account that
the Logs Router will use to access your Cloud KMS key. Use
GetCmekSettings to
obtain the service account ID.
See Enabling CMEK for Logs
Router
for more information.
string service_account_id = 3 [(.google.api.field_behavior) = OUTPUT_ONLY];
Name | Description |
value | ByteString The bytes for serviceAccountId to set. |
Type | Description |
CmekSettings.Builder | This builder for chaining. |
setUnknownFields(UnknownFieldSet unknownFields)
public final CmekSettings.Builder setUnknownFields(UnknownFieldSet unknownFields)
Name | Description |
unknownFields | UnknownFieldSet |
Type | Description |
CmekSettings.Builder |