Google Cloud KMS should be available as an encryption provider using envelope encryption (KEK-DEK). Documents on this feature: [A Plan For Kubernetes Secrets](https://docs.google.com/document/d/1JAwPuZg47UhfRVlof-lMw08OJztunW8pvTNxDK3rCF8/edit) [Encryption of secrets at the database layer](https://github.com/kubernetes/community/pull/607/files) [Implementing KMS plugins](https://docs.google.com/document/d/19SbqLrSC_MpmxbLCxasubRJLaZxgqfw1KeIwg3fHHLU/edit?usp=sharing) /kind feature