OCNORA

Google Cloud KMS

Google CloudOAuth 2.0credential probe

Encrypt, decrypt and sign with Cloud KMS keys (Google OAuth2).

OCNORA ships 72 typed Google Cloud KMS operations. Each node has a schema-driven form, input and output tables beside its settings, and is pre-flighted by Workflow Health before your first real run.

Operations 72

  • Approve Proposal
    Approves a SingleTenantHsmInstanceProposal for a given SingleTenantHsmInstance.
    cloud_kms.approve_proposal
  • Asymmetric Decrypt Crypto Key Version
    Decrypts data that was encrypted with a public key retrieved from GetPublicKey corresponding to a CryptoKeyVersion with CryptoKey.purpose ASYMMETRIC_DECRYPT.
    cloud_kms.asymmetric_decrypt_crypto_key_version
  • Create Crypto Key
    Create a new CryptoKey within a KeyRing.
    cloud_kms.create_crypto_key
  • Create Crypto Key Version
    Create a new CryptoKeyVersion in a CryptoKey.
    cloud_kms.create_crypto_key_version
  • Create Ekm Connection
    Creates a new EkmConnection in a given Project and Location.
    cloud_kms.create_ekm_connection
  • Create Import Job
    Create a new ImportJob within a KeyRing.
    cloud_kms.create_import_job
  • Create Key Handle
    Creates a new KeyHandle, triggering the provisioning of a new CryptoKey for CMEK use with the given resource type in the configured key project and the same location.
    cloud_kms.create_key_handle
  • Create Key Ring
    Create a new KeyRing in a given Project and Location.
    cloud_kms.create_key_ring
  • Create Proposal
    Creates a new SingleTenantHsmInstanceProposal for a given SingleTenantHsmInstance.
    cloud_kms.create_proposal
  • Create Single Tenant Hsm Instance
    Creates a new SingleTenantHsmInstance in a given Project and Location.
    cloud_kms.create_single_tenant_hsm_instance
  • Decapsulate Crypto Key Version
    Decapsulates data that was encapsulated with a public key retrieved from GetPublicKey corresponding to a CryptoKeyVersion with CryptoKey.purpose KEY_ENCAPSULATION.
    cloud_kms.decapsulate_crypto_key_version
  • Decrypt
    Decrypt base64 ciphertext with a Cloud KMS symmetric key; emits text.
    cloud_kms.decrypt
  • Delete Crypto Key
    Permanently deletes the given CryptoKey.
    cloud_kms.delete_crypto_key
  • Delete Crypto Key Version
    Permanently deletes the given CryptoKeyVersion.
    cloud_kms.delete_crypto_key_version
  • Delete Key Ring
    Permanently deletes the given KeyRing.
    cloud_kms.delete_key_ring
  • Delete Proposal
    Deletes a SingleTenantHsmInstanceProposal.
    cloud_kms.delete_proposal
  • Destroy Crypto Key Version
    Schedule a CryptoKeyVersion for destruction.
    cloud_kms.destroy_crypto_key_version
  • Encrypt
    Encrypt text with a Cloud KMS symmetric key; emits base64 ciphertext.
    cloud_kms.encrypt
  • Execute Proposal
    Executes a SingleTenantHsmInstanceProposal for a given SingleTenantHsmInstance.
    cloud_kms.execute_proposal
  • Export Trusted Key Wrapped Crypto Key Version Crypto Key Version
    Exports a CryptoKeyVersion with a trusted key.
    cloud_kms.export_trusted_key_wrapped_crypto_key_version_crypto_key_version
  • Generate Random Bytes Location
    Generate random bytes using the Cloud KMS randomness source in the provided location.
    cloud_kms.generate_random_bytes_location
  • Get Autokey Config Folder
    Returns the AutokeyConfig for a folder or project.
    cloud_kms.get_autokey_config_folder
  • Get Autokey Config Project
    Returns the AutokeyConfig for a folder or project.
    cloud_kms.get_autokey_config_project
  • Get Crypto Key
    Returns metadata for a given CryptoKey, as well as its primary CryptoKeyVersion.
    cloud_kms.get_crypto_key
  • Get Crypto Key Version
    Returns metadata for a given CryptoKeyVersion.
    cloud_kms.get_crypto_key_version
  • Get Ekm Config Location
    Returns the EkmConfig singleton resource for a given project and location.
    cloud_kms.get_ekm_config_location
  • Get Ekm Connection
    Returns metadata for a given EkmConnection.
    cloud_kms.get_ekm_connection
  • Get Import Job
    Returns metadata for a given ImportJob.
    cloud_kms.get_import_job
  • Get Kaj Policy Config Folder
    Gets the KeyAccessJustificationsPolicyConfig for a given organization, folder, or project.
    cloud_kms.get_kaj_policy_config_folder
  • Get Kaj Policy Config Organization
    Gets the KeyAccessJustificationsPolicyConfig for a given organization, folder, or project.
    cloud_kms.get_kaj_policy_config_organization
  • Get Kaj Policy Config Project
    Gets the KeyAccessJustificationsPolicyConfig for a given organization, folder, or project.
    cloud_kms.get_kaj_policy_config_project
  • Get Key Handle
    Returns the KeyHandle.
    cloud_kms.get_key_handle
  • Get Key Ring
    Returns metadata for a given KeyRing.
    cloud_kms.get_key_ring
  • Get Location
    Gets information about a location.
    cloud_kms.get_location
  • Get Operation
    Gets the latest state of a long-running operation.
    cloud_kms.get_operation
  • Get Proposal
    Returns metadata for a given SingleTenantHsmInstanceProposal.
    cloud_kms.get_proposal
  • Get Public Key Crypto Key Version
    Returns the public key for the given CryptoKeyVersion.
    cloud_kms.get_public_key_crypto_key_version
  • Get Retired Resource
    Retrieves a specific RetiredResource resource, which represents the record of a deleted CryptoKey.
    cloud_kms.get_retired_resource
  • Get Single Tenant Hsm Instance
    Returns metadata for a given SingleTenantHsmInstance.
    cloud_kms.get_single_tenant_hsm_instance
  • Import Crypto Key Version
    Import wrapped key material into a CryptoKeyVersion.
    cloud_kms.import_crypto_key_version
  • Import Trusted Key Wrapped Crypto Key Version Crypto Key Version
    Import wrapped key material into a CryptoKeyVersion with a trusted key.
    cloud_kms.import_trusted_key_wrapped_crypto_key_version_crypto_key_version
  • List Crypto Key Versions
    Lists CryptoKeyVersions.
    cloud_kms.list_crypto_key_versions
  • List Ekm Connections
    Lists EkmConnections.
    cloud_kms.list_ekm_connections
  • List Import Jobs
    Lists ImportJobs.
    cloud_kms.list_import_jobs
  • List Key Handles
    Lists KeyHandles.
    cloud_kms.list_key_handles
  • List Key Rings
    Lists KeyRings.
    cloud_kms.list_key_rings
  • List Keys
    List the crypto keys in a Cloud KMS key ring.
    cloud_kms.list_keys
  • List Locations
    Lists information about the supported locations for this service.
    cloud_kms.list_locations
Show 24 more
  • List Proposals
    Lists SingleTenantHsmInstanceProposals.
    cloud_kms.list_proposals
  • List Retired Resources
    Lists the RetiredResources which are the records of deleted CryptoKeys.
    cloud_kms.list_retired_resources
  • List Single Tenant Hsm Instances
    Lists SingleTenantHsmInstances.
    cloud_kms.list_single_tenant_hsm_instances
  • Mac Sign Crypto Key Version
    Signs data using a CryptoKeyVersion with CryptoKey.purpose MAC, producing a tag that can be verified by another source with the same key.
    cloud_kms.mac_sign_crypto_key_version
  • Mac Verify Crypto Key Version
    Verifies MAC tag using a CryptoKeyVersion with CryptoKey.purpose MAC, and returns a response that indicates whether or not the verification was successful.
    cloud_kms.mac_verify_crypto_key_version
  • Raw Decrypt Crypto Key Version
    Decrypts data that was originally encrypted using a raw cryptographic mechanism.
    cloud_kms.raw_decrypt_crypto_key_version
  • Raw Encrypt Crypto Key Version
    Encrypts data using portable cryptographic primitives.
    cloud_kms.raw_encrypt_crypto_key_version
  • Restore Crypto Key Version
    Restore a CryptoKeyVersion in the DESTROY_SCHEDULED state.
    cloud_kms.restore_crypto_key_version
  • Show Effective Autokey Config Folder
    Returns the effective Cloud KMS Autokey configuration for a given project or folder.
    cloud_kms.show_effective_autokey_config_folder
  • Show Effective Autokey Config Project
    Returns the effective Cloud KMS Autokey configuration for a given project or folder.
    cloud_kms.show_effective_autokey_config_project
  • Show Effective Key Access Justifications Enrollment Config Project
    Returns the KeyAccessJustificationsEnrollmentConfig of the resource closest to the given project in hierarchy.
    cloud_kms.show_effective_key_access_justifications_enrollment_config_project
  • Show Effective Key Access Justifications Policy Config Project
    Returns the KeyAccessJustificationsPolicyConfig of the resource closest to the given project in hierarchy.
    cloud_kms.show_effective_key_access_justifications_policy_config_project
  • Sign
    Sign the SHA-256 digest of text with an asymmetric KMS key version.
    cloud_kms.sign
  • Update Autokey Config Folder
    Updates the AutokeyConfig for a folder or a project.
    cloud_kms.update_autokey_config_folder
  • Update Autokey Config Project
    Updates the AutokeyConfig for a folder or a project.
    cloud_kms.update_autokey_config_project
  • Update Crypto Key
    Update a CryptoKey.
    cloud_kms.update_crypto_key
  • Update Crypto Key Version
    Update a CryptoKeyVersion's metadata.
    cloud_kms.update_crypto_key_version
  • Update Ekm Config Location
    Updates the EkmConfig singleton resource for a given project and location.
    cloud_kms.update_ekm_config_location
  • Update Ekm Connection
    Updates an EkmConnection's metadata.
    cloud_kms.update_ekm_connection
  • Update Kaj Policy Config Folder
    Updates the KeyAccessJustificationsPolicyConfig for a given organization, folder, or project.
    cloud_kms.update_kaj_policy_config_folder
  • Update Kaj Policy Config Organization
    Updates the KeyAccessJustificationsPolicyConfig for a given organization, folder, or project.
    cloud_kms.update_kaj_policy_config_organization
  • Update Kaj Policy Config Project
    Updates the KeyAccessJustificationsPolicyConfig for a given organization, folder, or project.
    cloud_kms.update_kaj_policy_config_project
  • Update Primary Version Crypto Key
    Update the version of a CryptoKey that will be used in Encrypt.
    cloud_kms.update_primary_version_crypto_key
  • Verify Connectivity Ekm Connection
    Verifies that Cloud KMS can successfully connect to the external key manager specified by an EkmConnection.
    cloud_kms.verify_connectivity_ekm_connection

Run your first Google Cloud KMS workflow today.

Create a free workspace, add the connection, pick a template or describe the workflow to Build with AI. Workflow Health checks it before it runs.