Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 
 
 

README.md

De-identification template submodule example

This example illustrates how to use the de-identification template submodule.

Prerequisites

  1. The De-identification template submodule requirements to using the submodule.
  2. A crypto_key and wrapped_key pair. Contact your Security Team to obtain the crypto_key and wrapped_key pair. The crypto_key location must be the same location used for the dlp_location. There is a Wrapped Key Helper python script which generates a wrapped key.
  3. The identity deploying the example must have permission to grant roles "roles/cloudkms.cryptoKeyDecrypter" and "roles/cloudkms.cryptoKeyEncrypter" in the KMS crypto_key. It will be granted to the dataflow_service_account.

Troubleshooting

If you encounter problems in the apply execution check the Troubleshooting Guide.

Inputs

Name Description Type Default Required
crypto_key The full resource name of the Cloud KMS key that wraps the data crypto key used by DLP. string n/a yes
dataflow_service_account The Service Account email that will be used to identify the VMs in which the jobs are running. string n/a yes
project_id The ID of the project in which to provision resources. string n/a yes
terraform_service_account The email address of the service account that will run the Terraform config. string n/a yes
wrapped_key The base64 encoded data crypto key wrapped by KMS. string n/a yes

Outputs

Name Description
template_id The ID of the Cloud DLP de-identification template that is created.