Status: IN
Each project's service agent performs CMEK encrypt/decrypt operations; end users do not need the CryptoKey Encrypter/Decrypter role to access CMEK-protected resources.
Source: entries/2026/03/11/kms-cmek.md
JSON