feat(secretmanager): Add Cloud SQL managed-rotation samples - #4490
suvidha-malaviya wants to merge 3 commits into
Conversation
There was a problem hiding this comment.
Code Review
This pull request introduces new Node.js samples for Google Cloud Secret Manager, enabling users to create secrets with specific types and manage regional secrets with Cloud SQL DB credentials, including managed rotation features. It also adds corresponding integration tests. The review feedback identifies a potential robustness issue in the test helper functions grantCloudSqlRole and revokeCloudSqlRole, where accessing policy.bindings directly could throw a TypeError if no bindings are set on the project. It is recommended to defensively default policy.bindings to an empty array.
| const [policy] = await resourcemanagerProjectsClient.getIamPolicy({ | ||
| resource: resource, | ||
| }); | ||
| let binding = policy.bindings.find(b => b.role === CLOUD_SQL_ROLE); |
There was a problem hiding this comment.
The IAM policy returned by getIamPolicy might not contain a bindings array if no bindings are currently set on the project. Accessing policy.bindings.find directly can throw a TypeError. Adding a defensive check or defaulting policy.bindings to an empty array ensures robustness.
const [policy] = await resourcemanagerProjectsClient.getIamPolicy({
resource: resource,
});
policy.bindings = policy.bindings || [];
let binding = policy.bindings.find(b => b.role === CLOUD_SQL_ROLE);| const [policy] = await resourcemanagerProjectsClient.getIamPolicy({ | ||
| resource: resource, | ||
| }); | ||
| const binding = policy.bindings.find(b => b.role === CLOUD_SQL_ROLE); |
There was a problem hiding this comment.
The IAM policy returned by getIamPolicy might not contain a bindings array if no bindings are currently set on the project. Accessing policy.bindings.find directly can throw a TypeError. Adding a defensive check or defaulting policy.bindings to an empty array ensures robustness.
const [policy] = await resourcemanagerProjectsClient.getIamPolicy({
resource: resource,
});
policy.bindings = policy.bindings || [];
const binding = policy.bindings.find(b => b.role === CLOUD_SQL_ROLE);getIamPolicy can return a policy with no bindings array when the project has none set. Default policy.bindings to [] before calling .find()/.push() in grantCloudSqlRole and revokeCloudSqlRole to avoid a TypeError.
dfb1a8b to
fd650f9
Compare
|
Here is the summary of changes. You are about to add 7 region tags.
This comment is generated by snippet-bot.
|
Description
Adds Node.js samples for Secret Manager's Cloud SQL managed-rotation feature (regional secrets only — this feature isn't available for global secrets):
regional_samples/createRegionalSecretWithCloudSqlCredentials.jsregional_samples/enableRegionalSecretManagedRotation.jsregional_samples/rotateRegionalSecret.jsregional_samples/updateRegionalSecretWithManagedRotationSchedule.js— reconfigures the recurring rotation schedule on a secret that already has managed rotation enabledregional_samples/getRegionalSecretType.js(regional)Also added two global scenario with secret-type:
createSecretWithType.js(global)getSecretType.js(global)Added test coverage for all of the above in
test/secretmanager.test.js.Checklist
npm test(see Testing)npm run lint(see Style)sqladmin.googleapis.com)-
CLOUD_SQL_INSTANCE/CLOUD_SQL_USER— a pre-provisioned, long-lived Cloud SQL instance + DB user for managed-rotation tests to point at-
GCLOUD_LOCATION— region for regional secrets (defaults tous-central1if unset; must match the Cloud SQL instance's region)- The identity running these tests additionally needs
resourcemanager.projects.getIamPolicy/setIamPolicyon the test project (e.g.roles/resourcemanager.projectIamAdmin)GoogleCloudPlatform/nodejs-docs-samples. Not a fork.