Skip to content

feat(secretmanager): Adding CMEK sample#5449

Open
khilan-crest wants to merge 27 commits into
GoogleCloudPlatform:mainfrom
khilan-crest:golang_secretmanager_cmek_samples
Open

feat(secretmanager): Adding CMEK sample#5449
khilan-crest wants to merge 27 commits into
GoogleCloudPlatform:mainfrom
khilan-crest:golang_secretmanager_cmek_samples

Conversation

@khilan-crest

Copy link
Copy Markdown

Adding CMEK sample

Fixes #

Note: Before submitting a pull request, please open an issue for discussion if you are not associated with Google.

Checklist

  • I have followed Contributing Guidelines from CONTRIBUTING.MD
  • Tests pass: go test -v ./.. (see Testing)
  • Code formatted: gofmt (see Formatting)
  • Vetting pass: go vet (see Formatting)
  • These samples need a new API enabled in testing projects to pass (let us know which ones)
  • These samples need a new/updated env vars in testing projects set to pass (let us know which ones)
  • This sample adds a new sample directory, and I updated the CODEOWNERS file with the codeowners for this sample
  • This sample adds a new Product API, and I updated the Blunderbuss issue/PR auto-assigner with the codeowners for this sample
  • Please merge this PR for me once it is approved

@product-auto-label product-auto-label Bot added api: secretmanager Issues related to the Secret Manager API. samples Issues that are directly related to samples. labels Jan 12, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello @khilan-crest, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request enhances the Google Cloud Go samples by providing practical examples for integrating Customer-Managed Encryption Keys (CMEK) with Secret Manager. It offers clear, runnable code snippets for both globally and regionally managed secrets, enabling developers to implement robust encryption strategies using their own KMS keys. The addition of these samples improves the library's coverage for advanced security configurations.

Highlights

  • New CMEK Sample for Secret Manager: Introduces a new Go sample demonstrating how to create a Google Cloud Secret Manager secret encrypted with a Customer-Managed Encryption Key (CMEK).
  • Regional CMEK Support: Adds a specific sample for creating regional Secret Manager secrets with CMEK, showcasing how to specify a regional KMS key and endpoint.
  • Comprehensive Testing: Includes new test cases (TestCreateSecretWithCMEK and TestCreateRegionalSecretWithCMEK) to validate the functionality of creating secrets with CMEK, ensuring proper integration and verification of the KMS key.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds new samples for creating secrets with Customer-Managed Encryption Keys (CMEK) in Secret Manager, for both global and regional secrets. The changes include the sample code itself and corresponding system tests. The implementation is straightforward and the tests are comprehensive, verifying the secret creation and the CMEK configuration. I've found one minor issue in a code comment, which I've detailed below. Overall, this is a great addition.

Comment thread secretmanager/regional_samples/create_regional_secret_with_cmek.go Outdated
…hub.com:khilan-crest/golang-samples into golang_secretmanager_cmek_samples
@khilan-crest khilan-crest marked this pull request as ready for review January 29, 2026 06:27
@khilan-crest khilan-crest requested review from a team as code owners January 29, 2026 06:27
@snippet-bot

snippet-bot Bot commented Jan 29, 2026

Copy link
Copy Markdown

Here is the summary of changes.

You are about to add 30 region tags.

This comment is generated by snippet-bot.
If you find problems with this result, please file an issue at:
https://github.com/googleapis/repo-automation-bots/issues.
To update this comment, add snippet-bot:force-run label or use the checkbox below:

  • Refresh this comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: secretmanager Issues related to the Secret Manager API. samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant