Status: OUT
CMEK key lifecycle is the single governance surface for data persistence across GCP: a key that protects GCS objects (conditionally voiding eleven-nines durability on destruction), Spanner databases (auto-deleted after 30 days of key unavailability), and other CMEK-integrated services creates cross-service blast radius from a single key management decision — rotation is safe but destruction or revocation cascades across all dependent services simultaneously.