! IAM () .
svcacct@project2.iam.gserviceaccount.com project1, , :
$ KMS_KEY_RESOURCE_NAME=projects/project1/locations/${location}/keyRings/${keyring_name}/cryptoKeys/${crypto_key_name}
$ gcloud kms keys add-iam-policy-binding \
--location ${location} ${KMS_KEY_RESOURCE_NAME} \
--member serviceAccount:svcacct@project2.iam.gserviceaccount.com \
--role roles/cloudkms.cryptoKeyDecrypter
, svcacct@project2.iam.gserviceaccount.com " " "" KeyRing Key, http://console.cloud.google.com/iam-admin/kms?project=project1