Google Cloud Platform allows for customer supplied disk encryption keys as an option to using Google supplied disk encryption keys.
However, to use customer supplied keys, you must send the key (either raw or wrapped by a google public key) to Google APIs.
In terms of security guarantees, it doesn't seem like this situation is any better than using Google provided encryption keys as the customer supplied keys are made visible to Google.
Is there some benefit or scenario of customer supplied keys I'm missing here?