Skip to content

feat(secretmanager): Add Cloud SQL managed-rotation samples - #4490

Open
suvidha-malaviya wants to merge 3 commits into
GoogleCloudPlatform:mainfrom
suvidha-malaviya:cloudsql-managed-rotation
Open

suvidha-malaviya wants to merge 3 commits into
GoogleCloudPlatform:mainfrom
suvidha-malaviya:cloudsql-managed-rotation

Conversation

@suvidha-malaviya

Copy link
Copy Markdown

Description

Adds Node.js samples for Secret Manager's Cloud SQL managed-rotation feature (regional secrets only — this feature isn't available for global secrets):

  • regional_samples/createRegionalSecretWithCloudSqlCredentials.js
  • regional_samples/enableRegionalSecretManagedRotation.js
  • regional_samples/rotateRegionalSecret.js
  • regional_samples/updateRegionalSecretWithManagedRotationSchedule.js — reconfigures the recurring rotation schedule on a secret that already has managed rotation enabled
  • regional_samples/getRegionalSecretType.js (regional)

Also added two global scenario with secret-type:

  • createSecretWithType.js (global)
  • getSecretType.js (global)

Added test coverage for all of the above in test/secretmanager.test.js.

Checklist

  • I have followed guidelines from CONTRIBUTING.MD and Samples Style Guide
  • Tests pass: npm test (see Testing)
  • Lint pass: npm run lint (see Style)
  • Required CI tests pass (see CI testing)
  • These samples need a new API enabled in testing projects to pass (let us know which ones) — Cloud SQL Admin API (sqladmin.googleapis.com)
  • These samples need a new/updated env vars in testing projects set to pass (let us know which ones):
    - CLOUD_SQL_INSTANCE / CLOUD_SQL_USER — a pre-provisioned, long-lived Cloud SQL instance + DB user for managed-rotation tests to point at
    - GCLOUD_LOCATION — region for regional secrets (defaults to us-central1 if unset; must match the Cloud SQL instance's region)
    - The identity running these tests additionally needs resourcemanager.projects.getIamPolicy/setIamPolicy on the test project (e.g. roles/resourcemanager.projectIamAdmin)
  • This pull request is from a branch created directly off of GoogleCloudPlatform/nodejs-docs-samples. Not a fork.
  • This sample adds a new sample directory, and I updated the CODEOWNERS file with the codeowners for this sample
  • This sample adds a new sample directory, and I created GitHub Actions workflow for this sample
  • This sample adds a new Product API, and I updated the Blunderbuss issue/PR auto-assigner with the codeowners for this sample
  • Please merge this PR for me once it is approved

@product-auto-label product-auto-label Bot added api: secretmanager Issues related to the Secret Manager API. samples Issues that are directly related to samples. labels Sep 25, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces new Node.js samples for Google Cloud Secret Manager, enabling users to create secrets with specific types and manage regional secrets with Cloud SQL DB credentials, including managed rotation features. It also adds corresponding integration tests. The review feedback identifies a potential robustness issue in the test helper functions grantCloudSqlRole and revokeCloudSqlRole, where accessing policy.bindings directly could throw a TypeError if no bindings are set on the project. It is recommended to defensively default policy.bindings to an empty array.

Comment on lines +78 to +81
const [policy] = await resourcemanagerProjectsClient.getIamPolicy({
resource: resource,
});
let binding = policy.bindings.find(b => b.role === CLOUD_SQL_ROLE);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The IAM policy returned by getIamPolicy might not contain a bindings array if no bindings are currently set on the project. Accessing policy.bindings.find directly can throw a TypeError. Adding a defensive check or defaulting policy.bindings to an empty array ensures robustness.

    const [policy] = await resourcemanagerProjectsClient.getIamPolicy({
      resource: resource,
    });
    policy.bindings = policy.bindings || [];
    let binding = policy.bindings.find(b => b.role === CLOUD_SQL_ROLE);

Comment on lines +112 to +115
const [policy] = await resourcemanagerProjectsClient.getIamPolicy({
resource: resource,
});
const binding = policy.bindings.find(b => b.role === CLOUD_SQL_ROLE);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The IAM policy returned by getIamPolicy might not contain a bindings array if no bindings are currently set on the project. Accessing policy.bindings.find directly can throw a TypeError. Adding a defensive check or defaulting policy.bindings to an empty array ensures robustness.

    const [policy] = await resourcemanagerProjectsClient.getIamPolicy({
      resource: resource,
    });
    policy.bindings = policy.bindings || [];
    const binding = policy.bindings.find(b => b.role === CLOUD_SQL_ROLE);

getIamPolicy can return a policy with no bindings array when the
project has none set. Default policy.bindings to [] before calling
.find()/.push() in grantCloudSqlRole and revokeCloudSqlRole to avoid
a TypeError.
@suvidha-malaviya
suvidha-malaviya force-pushed the cloudsql-managed-rotation branch from dfb1a8b to fd650f9 Compare September 25, 2026 12:31
@suvidha-malaviya
suvidha-malaviya marked this pull request as ready for review September 25, 2026 12:33
@suvidha-malaviya
suvidha-malaviya requested review from a team as code owners September 25, 2026 12:33
@snippet-bot

snippet-bot Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Here is the summary of changes.

You are about to add 7 region tags.

This comment is generated by snippet-bot.
If you find problems with this result, please file an issue at:
https://github.com/googleapis/repo-automation-bots/issues.
To update this comment, add snippet-bot:force-run label or use the checkbox below:

  • Refresh this comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: secretmanager Issues related to the Secret Manager API. samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants