Configure bring your own key BYOK for Google CDE
- Updated: 2024/05/28
Configure bring your own key BYOK for Google CDE
To leverage BYOK (bring your own key) license for Google Custom Document Extractor (CDE) processor, follow these configuration steps.
Prerequisites
- Ensure that you have assigned the Document AI Viewer or Document AI Editor role and have created a service account on your Google Cloud Platform. See Create service accounts and IAM roles for Document AI.
- Ensure that you have created a service account key for your Google project and downloaded the .json file from your Google Cloud Platform. See Create a service account key.
- Log in as the
AAE_Locker_Admin
user type.
Procedure
-
Create a custom role for Credential Vault locker.
-
Create a credential in Credential Vault for Google service
account.
-
Create a locker to store the key.
- Navigate to the Lockers tab and click Create locker.
-
Provide a name for the locker, such as
google-cde-locker
. -
Select the
google-cde-credential
and click the right arrow to move the credential to the Selected column. -
In the Consumers tab, select the
google-cde-credential-role
and click the right arrow to move the credential to the Selected column. - Click Create locker.