googlekms-configure-connection-profile
Connection Profile Name: Enter a name that uniquely identifies the external resource.
Namespace:.Select the namespace where the profile will be stored. All users who will use this profile must have READ and SELECT permissions on the namespace.
Endpoint Type: Select GoogleKMS.
Key URL: Specify the resource ID for the key to be used by Shield components associated with this profile (see Cloud Key Management Service > Documentation > Guides > Getting a Cloud KMS resource ID > Getting the ID for a key and version), for example,
projects/myproject3-412123/locations/us-west2/keyRings/MyKeyRing/cryptoKeys/MyKey.Service Account Key Path: Upload the file, or specify the path to and name of the service account key you uploaded previously . Alternatively, leave blank to use the default credentials for the KMS instance.