File: //snap/google-cloud-cli/current/help/man/man1/gcloud_storage_service-agent.1
.TH "GCLOUD_STORAGE_SERVICE\-AGENT" 1
.SH "NAME"
.HP
gcloud storage service\-agent \- manage a project's Cloud Storage service agent, which is used to perform Cloud KMS operations
.SH "SYNOPSIS"
.HP
\f5gcloud storage service\-agent\fR [\fB\-\-authorize\-cmek\fR=\fIAUTHORIZE_CMEK\fR] [\fIGCLOUD_WIDE_FLAG\ ...\fR]
.SH "DESCRIPTION"
\fBgcloud storage service\-agent\fR displays the Cloud Storage service agent,
which is used to perform Cloud KMS operations against your a default or supplied
project. If the project does not yet have a service agent, \fBgcloud storage
service\-agent\fR creates one.
.SH "EXAMPLES"
To show the service agent for your default project:
.RS 2m
$ gcloud storage service\-agent
.RE
To show the service account for \f5\fImy\-project\fR\fR:
.RS 2m
$ gcloud storage service\-agent \-\-project=my\-project
.RE
To authorize your default project to use a Cloud KMS key:
.RS 2m
$ gcloud storage service\-agent \e
\-\-authorize\-cmek=projects/key\-project/locations/us\-east1/\e
keyRings/key\-ring/cryptoKeys/my\-key
.RE
.SH "FLAGS"
.RS 2m
.TP 2m
\fB\-\-authorize\-cmek\fR=\fIAUTHORIZE_CMEK\fR
Adds appropriate encrypt/decrypt permissions to the specified Cloud KMS key.
This allows the Cloud Storage service agent to write and read Cloud
KMS\-encrypted objects in buckets associated with the service agent's project.
.RE
.sp
.SH "GCLOUD WIDE FLAGS"
These flags are available to all commands: \-\-access\-token\-file, \-\-account,
\-\-billing\-project, \-\-configuration, \-\-flags\-file, \-\-flatten,
\-\-format, \-\-help, \-\-impersonate\-service\-account, \-\-log\-http,
\-\-project, \-\-quiet, \-\-trace\-token, \-\-user\-output\-enabled,
\-\-verbosity.
Run \fB$ gcloud help\fR for details.
.SH "NOTES"
This variant is also available:
.RS 2m
$ gcloud alpha storage service\-agent
.RE