Provide Access to Destination Bucket
Finish the Project Setup and Key Download step for the session. The Session ID can be found in the email titled Action Required: Provide Access for Data Upload - Google Transfer Appliance.
Provide Access to KMS
- Prerequisite:Ensure you have the Cloud KMS Adminrole (
roles/cloudkms.admin) to provide access to the KMS key. - Find the Session ID in the email titled Action Required: Provide Access for Data Upload - Google Transfer Appliance.
- Find the KMS key in the 'Key resource n̦ame' field on the Appliance Detail page for the given session.
-
Go to the Cryptographic Keyspage in Google Cloud console.
-
Click the key ring that contains your asymmetric key.
-
Select the checkbox for the asymmetric key.
-
In the Info panel, click Add principal.
- Add principalsis displayed.
-
In the New principalsfield, enter the Transfer Appliance P4SA. It looks like the following example:
service- PROJECT_NUMBER @gcp-sa-transferappliance.iam.gserviceaccount.comIn this example,
PROJECT_NUMBERis the Google Cloud project number that your appliance is under. -
In the Select a rolefield, add the Cloud KMS CryptoKey Public Key Viewerrole.
-
Click the Add another roleand add Cloud KMS CryptoKey Decrypterrole.
-
Click Save.

