Atlas on GCP - CMK - Avoid Service account keys
We want to use our own GCP CMK keys to encrypt our environments deployed in Altas GCP
We read the document here: https://www.mongodb.com/docs/atlas/security-gcp-kms/#required-access and it states that we need to provide our Google Cloud Service Account Key.
Is there a way to use something like this: https://cloud.google.com/iam/docs/workload-identity-federation.
Summary: Use Identity and Access Management to grant permissions on GCP CMK instead of Service account keys.
1
vote

-
AdminJoel (Admin, MongoDB) commented
We have plans to release this soon and are currently defining the requirements. I can't commit to a timeline but it's planned. Thank you.