LinuxCommandLibrary
GitHubF-DroidGoogle Play Store

gcloud-kms-decrypt

decrypt data using Cloud KMS keys

TLDR

Decrypt file
$ gcloud kms decrypt --ciphertext-file=[encrypted.enc] --plaintext-file=[decrypted.txt] --key=[key] --keyring=[keyring] --location=[global]
copy
Decrypt from stdin
$ cat [encrypted.enc] | gcloud kms decrypt --ciphertext-file=- --plaintext-file=[output.txt] --key=[key] --keyring=[keyring] --location=[global]
copy
Decrypt to stdout
$ gcloud kms decrypt --ciphertext-file=[encrypted.enc] --plaintext-file=- --key=[key] --keyring=[keyring] --location=[global]
copy

SYNOPSIS

gcloud kms decrypt [options]

DESCRIPTION

gcloud kms decrypt uses Cloud Key Management Service to decrypt data that was previously encrypted with a Cloud KMS key. KMS provides centralized cryptographic key management, separating key storage and access control from the applications that use them.The decryption operation requires specifying the exact key, keyring, and location used during encryption. Access to decrypt is controlled by IAM permissions on the key, allowing fine-grained control over who can decrypt sensitive data. This enables secure secrets management where encrypted data can be stored in version control or configuration files while keys remain secured in KMS.The command supports reading from files or stdin and writing to files or stdout, enabling integration into pipelines and scripts. Cloud KMS is commonly used for envelope encryption, where data encryption keys are themselves encrypted by KMS keys, providing an additional security layer. This is the standard pattern for encrypting application secrets, database credentials, and other sensitive configuration data in Google Cloud environments.

PARAMETERS

--ciphertext-file FILE

Encrypted input file.
--plaintext-file FILE
Decrypted output file.
--key KEY
Crypto key name.
--keyring KEYRING
Key ring name.
--location LOCATION
Key location.
--help
Display help information.

CAVEATS

Requires KMS permissions. Key must match encryption key. Location must be correct.

HISTORY

gcloud kms decrypt is part of the Google Cloud SDK for Cloud KMS, Google's managed service for cryptographic key management.

SEE ALSO

gcloud(1)

Braincup
Open source brain training for math, memory and focus
Braincup mini-games
41 mini-games · Apache-2.0
No ads · No tracking
Play in browser
Download Braincup on the App StoreGet Braincup on Google PlayGet Braincup on F-Droid
276 stars
From the maker of Linux Command Library
Copied to clipboard
Braincup
Open source brain training for math, memory and focus. 41 mini-games, from mental arithmetic to Sudoku, N-Back and Solo Chess.
Apache-2.0 licensed · No ads · No tracking · No account
From the maker of Linux Command Library
Download Braincup on the App StoreGet Braincup on Google PlayGet Braincup on F-Droid