创建带CMEK的Vertex AI端点时遭遇in_use_customer_managed_encryption_keys配额超限及配额疑问咨询
Let’s walk through your problem and clear up the confusion around that quota error:
What’s Going On
When you tried to create a Vertex AI endpoint with a Customer-Managed Encryption Key (CMEK), you ran into this 429 quota error:
Failed to create endpoint...The following quota metrics exceed quota limits: aiplatform.googleapis.com/in_use_customer_managed_encryption_keys
But when you checked the IAM & Admin > Quotas page for your target region, the "In use customer managed encryption keys per region" quota showed:
- Limit: 1
- Current usage: 0
Answering Your Core Question: Do I need usage < limit to create the endpoint?
Short answer: Yes, but there’s a key nuance here. Creating a CMEK-protected endpoint consumes one quota unit immediately. Since your limit is 1 and usage is 0, this should work—but the error suggests the system isn’t recognizing that available slot.
Possible reasons for the discrepancy:
- Console Stats Delay: Quota usage metrics in the console can take 10-15 minutes to update. It’s possible a previous resource (even a deleted one) is still being counted temporarily.
- Hidden Resource Lock: Sometimes orphaned or partially deleted CMEK-protected resources (like endpoints that failed to clean up fully) can hold a quota slot without showing up in the usage count.
- Quota Metric Scope: The
aiplatform.googleapis.com/in_use_customer_managed_encryption_keysmetric counts all CMEK-protected Vertex AI resources in the region—not just endpoints. Double-check if you have other resources (like models or datasets) using CMEK that might be using the slot.
Why Your Quota Increase Request Didn’t Get a Direct Answer
Google’s quota support teams typically focus on processing the request logistics (like cost implications) in their initial response, rather than diving into technical quota mechanics. They likely didn’t catch your specific question about single-endpoint requirements amid the request details.
Next Steps to Fix This
- Wait and Retry: Give the console 15-20 minutes to sync usage data, then try creating the endpoint again.
- Audit Region Resources: Scan your region for any CMEK-protected Vertex AI resources (even deleted ones in the "Recycle Bin" if available) that might be consuming the quota.
- Follow Up on Your Request: Reply to the support email, restating your question clearly: "I’m trying to create a single CMEK-protected endpoint, but hit a quota error despite showing 0/1 usage. Does creating one endpoint require a quota limit higher than 1?" Include the error message and console stats screenshot if possible to speed up their response.
内容的提问来源于stack exchange,提问作者Chris

