What we really want to control about our keys is generally, who can use them, for what purposes, and with what configuration. — TL;DR As a security architect, you might think you need to centralize your KMS keys into a single project for security because you would centralize administration when you do it on-prem, but you’re probably better off decentralizing when you move to Google Cloud. By this I mean allowing application owners to…