This example illustrates how to use the de-identification template submodule.
- The De-identification template submodule requirements to using the submodule.
- A
crypto_keyandwrapped_keypair. Contact your Security Team to obtain thecrypto_keyandwrapped_keypair. Thecrypto_keylocation must be the same location used for thedlp_location. There is a Wrapped Key Helper python script which generates a wrapped key. - The identity deploying the example must have permission to grant roles "roles/cloudkms.cryptoKeyDecrypter" and "roles/cloudkms.cryptoKeyEncrypter" in the KMS
crypto_key. It will be granted to thedataflow_service_account.
If you encounter problems in the apply execution check the Troubleshooting Guide.
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| crypto_key | The full resource name of the Cloud KMS key that wraps the data crypto key used by DLP. | string |
n/a | yes |
| dataflow_service_account | The Service Account email that will be used to identify the VMs in which the jobs are running. | string |
n/a | yes |
| project_id | The ID of the project in which to provision resources. | string |
n/a | yes |
| terraform_service_account | The email address of the service account that will run the Terraform config. | string |
n/a | yes |
| wrapped_key | The base64 encoded data crypto key wrapped by KMS. | string |
n/a | yes |
| Name | Description |
|---|---|
| template_id | The ID of the Cloud DLP de-identification template that is created. |