Secret replication policy
Secrets are a global resource entity; however, secret payloads (the underlying secret material) are stored locally within a region. Some regulated customers such as financial and healthcare institutions may have strict regionalization requirements, while other customers may want to store the secret near the data. A replication policy allows control over where secret payloads are stored.
There are two replication policy types: automatic and user-managed.
Automatic
With the automatic policy type, the replication of the secret is managed by Google. This policy provides the highest level of availability:
- When a secret has an automatic replication policy, its payload data is copied as many times as needed. This is the easiest way to set things up, and most users should choose it. This is the policy that is used by default when a secret is created using the Google Cloud CLI or the web UI.
- A secret that is automatically replicated is stored in...