unless I just misunderstood and the KMS key is sin...
# google-cloud
b
unless I just misunderstood and the KMS key is single and its just used to decrypt the local keys? This would make also sense.
g
secrets are encrypted via KMS and stored in an encrypted format https://cloud.google.com/sdk/gcloud/reference/kms/encrypt