ToolUp.Encryption.GoogleCloudKms 0.22.0

Prefix Reserved
dotnet add package ToolUp.Encryption.GoogleCloudKms --version 0.22.0
                    
NuGet\Install-Package ToolUp.Encryption.GoogleCloudKms -Version 0.22.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="ToolUp.Encryption.GoogleCloudKms" Version="0.22.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="ToolUp.Encryption.GoogleCloudKms" Version="0.22.0" />
                    
Directory.Packages.props
<PackageReference Include="ToolUp.Encryption.GoogleCloudKms" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add ToolUp.Encryption.GoogleCloudKms --version 0.22.0
                    
#r "nuget: ToolUp.Encryption.GoogleCloudKms, 0.22.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package ToolUp.Encryption.GoogleCloudKms@0.22.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=ToolUp.Encryption.GoogleCloudKms&version=0.22.0
                    
Install as a Cake Addin
#tool nuget:?package=ToolUp.Encryption.GoogleCloudKms&version=0.22.0
                    
Install as a Cake Tool

ToolUp.Encryption.GoogleCloudKms

GCP Cloud KMS-backed IBlobEncryptionKeyResolver for ToolUp.Platform (Phase 22a). Envelope encryption: the deployment's KMS symmetric CryptoKey (KEK) never leaves GCP. Each blob is encrypted with its own AES-256 data key (DEK) minted locally; the DEK is Encrypt'd under the KEK and the ciphertext (plus the KEK resource name) is stamped into the blob envelope's KeyId. A later read Decrypts it. The resolver holds no key state between calls (GP 12 rule 4).

Mirrors src/Encryption/AwsKms/ packaging. Server-only companion.

Quick start

open Google.Cloud.Kms.V1
open ToolUp.Encryption.GoogleCloudKms

let client = KeyManagementServiceClient.Create() // ADC from the env
let keyName = "projects/my-proj/locations/europe-west2/keyRings/blob/cryptoKeys/kek"
let resolver = GoogleCloudKmsKeyResolver.create client keyName
// wire via ServerApp.withEncryptedBlobStorage resolver

Per-scope KEKs (multi-tenant key custody):

let resolver =
    GoogleCloudKmsKeyResolver.createPerScope client (fun scope -> keyNameFor scope.ScopeId)

Behaviour

  • ResolveKey scope → mint a random AES-256 DEK locally → KMS Encrypt under the KEK; returns the plaintext DEK + a KeyId of gcp-kms:v1:{base64url(keyName)}.{base64(ciphertext)}.
  • ResolveKeyById keyId → recover the KEK resource name + ciphertext → KMS Decrypt. NOT_FOUND surfaces as KeyResolutionError.KeyNotFound; FAILED_PRECONDITION / PERMISSION_DENIED (disabled / destroyed key version) as KeyDestroyed (HTTP 410 Gone at the API boundary — crypto-shred); other gRPC failures as StorageFailure.

The DEK plaintext is generated in-process and only ever leaves as the Encrypt plaintext / Decrypt result — the KEK key material stays in KMS.

Verification

The resolver requires a live KMS CryptoKey (no offline fake — KMS has no local emulator and KeyManagementServiceClient is not practically mockable). Mirrors the env-gated live-arm convention of the AWS KMS resolver / AIProviders.Tests. Verify against a real key:

  1. Create a symmetric ENCRYPT_DECRYPT CryptoKey; grant the deployment service account cloudkms.cryptoKeyEncrypterDecrypter.
  2. ResolveKey → encrypt a blob → ResolveKeyById round-trips the DEK.
  3. Disable the key version → ResolveKeyById returns KeyDestroyed.

License

Apache-2.0.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.22.0 96 8/27/2026
0.21.0 105 8/26/2026
0.20.1 107 8/20/2026
0.20.0 102 8/19/2026