镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

feat(secretmanager): Add Cloud SQL managed-rotation samples - #14562

Open
suvidha-malaviya wants to merge 8 commits into
GoogleCloudPlatform:mainfrom
suvidha-malaviya:cloudsql-managed-rotation
Open

suvidha-malaviya wants to merge 8 commits into
GoogleCloudPlatform:mainfrom
suvidha-malaviya:cloudsql-managed-rotation

Conversation

@suvidha-malaviya

@suvidha-malaviya suvidha-malaviya commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Added samples for Secret Manager's Cloud SQL managed-rotation feature (regional secrets only — this feature isn't available for global secrets)

  • create_regional_secret_with_cloud_sql_credentials
  • enable_regional_secret_managed_rotation
  • rotate_regional_secret
  • update_regional_secret_with_managed_rotation_schedule — reconfigures the recurring rotation schedule on a secret that already has managed rotation enabled
  • get_regional_secret_type — reads back a regional secret's secret_type

Also added two global scenario with secret-type:

  • create_secret_with_type — create a secret restricted to a given secret_type (e.g. ACCESS_KEY, CERTIFICATE, OTHER_DB_CREDENTIALS, OTHER; CLOUD_SQL_DB_CREDENTIALS is reserved for regional secrets going through managed rotation)
  • get_secret_type — read back a secret's secret_type

Added test coverage for all of the above: test_create_regional_secret_with_cloud_sql_credentials, test_enable_regional_secret_managed_rotation, test_rotate_regional_secret, test_update_regional_secret_with_managed_rotation_schedule, test_get_regional_secret_type, test_create_secret_with_type, test_get_secret_type

Note: requires google-cloud-secret-manager>=2.30.0, which itself requires Python>=3.10 — this feature does not exist in 2.29.0 or earlier.

Checklist

  • I have followed Sample Guidelines from AUTHORING_GUIDE.MD
  • README is updated to include all relevant information
  • Tests pass: nox -s py-3.9 (see Test Environment Setup)
  • Lint pass: nox -s lint (see Test Environment Setup)
  • These samples need a new API enabled in testing projects to pass (Cloud SQL Admin API — sqladmin.googleapis.com)
  • These samples need a new/updated env vars in testing projects set to pass (let us know which ones)
    - CLOUD_SQL_INSTANCE / CLOUD_SQL_USER — a pre-provisioned, long-lived Cloud SQL instance + DB user for managed-rotation tests to point at (same pattern as this repo's other Cloud SQL-backed sample tests)
    - The identity running these tests additionally needs resourcemanager.projects.getIamPolicy/setIamPolicy on the test project (e.g. roles/resourcemanager.projectIamAdmin)
  • This sample adds a new sample directory, and I updated the CODEOWNERS file with the codeowners for this sample
  • This sample adds a new Product API, and I updated the Blunderbuss issue/PR auto-assigner with the codeowners for this sample
  • Please merge this PR for me once it is approved

@product-auto-label product-auto-label Bot added api: secretmanager Issues related to the Secret Manager API. samples Issues that are directly related to samples. labels Sep 1, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces new regional samples and corresponding tests for Google Cloud Secret Manager, specifically covering creating secrets with Cloud SQL credentials, enabling managed rotation, and triggering rotation. Additionally, the google-cloud-secret-manager dependency is updated to version 2.30.0 in requirements.txt. However, there are critical runtime issues in both enable_regional_secret_managed_rotation.py and rotate_regional_secret.py where the API request payloads incorrectly use the key parent instead of name for the secret's resource name, which will result in a ValueError at runtime.

Comment thread secretmanager/snippets/regional_samples/rotate_regional_secret.py
@suvidha-malaviya
suvidha-malaviya marked this pull request as ready for review September 1, 2026 07:03
@suvidha-malaviya
suvidha-malaviya requested review from a team as code owners September 1, 2026 07:03
@snippet-bot

snippet-bot Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Here is the summary of changes.

You are about to add 7 region tags.

This comment is generated by snippet-bot.
If you find problems with this result, please file an issue at:
https://github.com/googleapis/repo-automation-bots/issues.
To update this comment, add snippet-bot:force-run label or use the checkbox below:

  • Refresh this comment

# See the License for the specific language governing permissions and
"""
command line application and sample code for creating a new secret that is
eligible for Cloud SQL managed rotation.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lets update it to reflect the message better, something like:

Suggested change
eligible for Cloud SQL managed rotation.
command line application and sample code for creating a new secret with type CLOUD_SQL_DB_CREDENTIALS, eligible for managed rotation.

# This built-in identity is what you grant Cloud SQL IAM permissions to,
# so that Secret Manager can rotate the database password on its behalf.
print(
"Grant this identity Cloud SQL IAM permissions to enable rotation: "

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CLOUD SQL User rotate IAM permissions to enable managed rotation

# See the License for the specific language governing permissions and
"""
command line application and sample code for enabling managed rotation of
a Cloud SQL DB credentials secret.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
a Cloud SQL DB credentials secret.
command line application and sample code to enable managed rotation of a CLOUD_SQL_DB_CREDENTIALS typed secret

Enable managed rotation for a Cloud SQL DB credentials secret. This
links the secret to a Cloud SQL instance and database user, and can
only be called once per secret. It adds the secret's first version and
sets the matching password on the Cloud SQL user, taking the place of

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is confusing, please update it accordingly to the below suggestion.

Suggested change
sets the matching password on the Cloud SQL user, taking the place of
It validates and enables the rotation, adding a version and sets the passed password (optional).
Note: AddSecretVersion is disabled on the CLOUD_SQL_DB_CREDENTIALS currently and for any necesary manual rotations please trigger rotate_secret


instance_id is the bare Cloud SQL instance ID (e.g. "my-instance") --
not a connection name. Neither the project nor the region should be
included: passing "PROJECT_ID:INSTANCE_ID" (as gcloud's own

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lets not add this, I have created a bug to resolve this; technically we should resolve the error in gcloud rather than adding it in the documentation. Please let us know if you find any similar issues in the future

# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
"""
command line application and sample code for triggering a managed

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lets change it to triggering an adhoc rotation for the managed CLOUD_SQL_DB_CREDENTIALS typed secret

rotation_period_seconds: int,
) -> secretmanager_v1.Secret:
"""
Reconfigure the recurring rotation schedule on a secret that already

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On the update_regional_secret_with_managed_rotation_schedule sample across the 7 PRs, could we make two quick comment cleanups inside the [START secretmanager_update_regional_secret_with_managed_rotation_schedule] block?

Clarify when schedule updates are allowed: On the backend, setting rotation.next_rotation_time and rotation.rotation_period on a CLOUD_SQL_DB_CREDENTIALS secret does NOT require EnableManagedRotation to be called first (customers can configure the rotation schedule before or after enabling managed rotation). Also, UpdateSecret with rotation works on other secret types too if Pub/Sub topics are configured — what's unique to CLOUD_SQL_DB_CREDENTIALS is that Pub/Sub topics aren't required.**

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes updated

},
}

# Mask only the two subfields being set here, not the whole "rotation"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove internal testing notes from the update_mask comment: Since everything inside [START ...] / [END ...] is rendered verbatim on cloud.google.com, could we drop the parentheticals (confirmed empirically against a live project) (in Python/Go/PHP/Ruby) and (the same behavior confirmed against a live project in this same port's Go samples) (in Java/Node.js)?

secret_type: secretmanager.Secret.SecretType,
) -> secretmanager.Secret:
"""
Create a new secret with the given secret type restriction (e.g.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is not required, lets just add that CLOUD_SQL_DB_CREDENTIALS is only supported in the regional secret

…ation samples

Align docstrings and comments with other samples and clarify rotation schedule behavior.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: secretmanager Issues related to the Secret Manager API. samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants