This page shows you how to create a key ring in Cloud KMS. A key ring is the root resource for Cloud KMS keys and key versions. Each key ring exists within a given location. For more information about Cloud KMS resources, see Cloud KMS resources.
Before you begin
Before completing the tasks on this page, you need the following:
- A Google Cloud project resource to contain your Cloud KMS resources. This project is called your key project. We recommend that your key project does not contain any other Google Cloud resources. Enable the Cloud KMS API on your key project.
- The name of the location where you want to create your key ring. Choose a location that is near your other resources and that supports your chosen protection level. To view available locations and the protection levels they support, see Cloud KMS locations.
Required roles
To get the permissions that
you need to create key rings,
ask your administrator to grant you the
Cloud KMS Admin (roles/cloudkms.admin) IAM role on the project or a parent resource.
For more information about granting roles, see Manage access to projects, folders, and organizations.
This predefined role contains the permissions required to create key rings. To see the exact permissions that are required, expand the Required permissions section: