Security 2 documented workflows
Cloud KMS
Pro key-management and cryptographic workflows.
Documented workflows
2 workflows- key rings, crypto keys, versions
- encrypt/decrypt/sign/verify
Service boundaries
- [prod_only] HSM (physical FIPS 140-2 Level 3 hardware) and EKM (external key manager providers).
- Import jobs and Cloud HSM level enforcement are not implemented.
- key rings, crypto keys, versions: Local REST facade exists.
- encrypt/decrypt/sign/verify: Crypto operation parity needs SDK and IAM tests.
- Audited metadata survives restart while the LocalCloud volume is retained
- External runtime/data-plane side effects, if any, have separate lifecycle and recovery limits.
Next steps
- AI agent local testing: prompts and endpoint routing for local workflows.
- Local cloud for AI agents: give agent-written cloud code a credentialless target.
- Compatibility: compare all 27 service guides.
- Configuration: service selection, tiers, and runtime precedence.