Introduction:
When I first moved from AWS to GCP, I expected things to work the same. In AWS, if my IAM role has kms:Encrypt and kms:Decrypt, I can upload and download S3 objects encrypted with KMS (SSE-KMS).
So when I set up my GKE cluster in GCP, I