Skip to content

Conversation

@dhavalbhensdadiya-crest
Copy link

@dhavalbhensdadiya-crest dhavalbhensdadiya-crest commented Jan 27, 2026

Description

Added samples for below operations in global and regional scope:

  1. Create secret with rotation
  2. Update secret with rotation
  3. Remove rotation from secret
  4. Create secret with topic

Fixes #

Note: Before submitting a pull request, please open an issue for discussion if you are not associated with Google.

Checklist

  • I have followed Sample Format Guide
  • pom.xml parent set to latest shared-configuration
  • Appropriate changes to README are included in PR
  • These samples need a new API enabled in testing projects to pass (let us know which ones) (Pub/Sub API)
  • These samples need a new/updated env vars in testing projects set to pass (let us know which ones) (GOOGLE_CLOUD_PUBSUB_TOPIC)
  • Tests pass: mvn clean verify required
  • Lint passes: mvn -P lint checkstyle:check required
  • Static Analysis: mvn -P lint clean compile pmd:cpd-check spotbugs:check advisory only
  • This sample adds a new sample directory, and I updated the CODEOWNERS file with the codeowners for this sample
  • This sample adds a new Product API, and I updated the Blunderbuss issue/PR auto-assigner with the codeowners for this sample
  • Please merge this PR for me once it is approved

@product-auto-label product-auto-label bot added samples Issues that are directly related to samples. api: secretmanager Issues related to the Secret Manager API. labels Jan 27, 2026
@snippet-bot
Copy link

snippet-bot bot commented Jan 27, 2026

Here is the summary of changes.

You are about to add 24 region tags.

This comment is generated by snippet-bot.
If you find problems with this result, please file an issue at:
https://github.com/googleapis/repo-automation-bots/issues.
To update this comment, add snippet-bot:force-run label or use the checkbox below:

  • Refresh this comment

@gemini-code-assist
Copy link
Contributor

Summary of Changes

Hello @dhavalbhensdadiya-crest, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly expands the Google Cloud Secret Manager Java samples by introducing a suite of new examples for advanced secret management features. It provides clear, executable code for creating secrets with rotation policies, expiration times, customer-managed encryption keys (CMEK), and Pub/Sub topic notifications. Additionally, it includes samples for managing resource tags associated with secrets. These additions are available for both global and regional Secret Manager instances, enhancing the utility and completeness of the sample library for developers.

Highlights

  • Secret Rotation Samples: New samples demonstrating how to create, update, and remove rotation policies for secrets, including setting next rotation times and periods.
  • Secret Expiration Samples: Added samples for creating secrets with a defined expiration time and for updating or deleting this expiration policy.
  • CMEK Integration Samples: Introduced samples for creating secrets encrypted with Customer-Managed Encryption Keys (CMEK).
  • Pub/Sub Topic Samples: New samples for associating Pub/Sub topics with secrets for notification purposes during creation and updates.
  • Secret Tag Management Samples: Samples for binding, listing, and deleting resource tags on secrets.
  • Global and Regional Scope Coverage: All new functionalities are provided with distinct samples for both global and regional Secret Manager configurations.
  • Documentation Updates: The README.md has been updated to include necessary environment variables (KMS keys, Pub/Sub topic) and IAM permissions for running the new samples.
  • Comprehensive Testing: Corresponding integration tests have been added or updated to validate the functionality of all new samples.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds a comprehensive set of new samples for Google Cloud Secret Manager, focusing on secret rotation, expiration, CMEK, topics, and tags for both global and regional secrets. The changes include new Java sample files, corresponding integration tests, and updates to the README with necessary setup instructions. The code is well-structured and the new samples are valuable additions. I have one suggestion to improve the clarity of the setup instructions in the README file.


```text
$ export GOOGLE_CLOUD_PROJECT=<your-project-id-here>
$ export GOOGLE_CLOUD_REGIONAL_KMS_KEY=<full-name-of-regional-kms-key> (region same as location)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The comment (region same as location) is a bit ambiguous and could lead to confusion. To improve clarity for users, it would be better to be more explicit about which location this refers to. For instance, you could clarify that it's the location used for regional secret samples.

Suggested change
$ export GOOGLE_CLOUD_REGIONAL_KMS_KEY=<full-name-of-regional-kms-key> (region same as location)
$ export GOOGLE_CLOUD_REGIONAL_KMS_KEY=<full-name-of-regional-kms-key> (region must match the location of regional secrets)

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
@dhavalbhensdadiya-crest dhavalbhensdadiya-crest force-pushed the feature/rotation-create-update-delete branch from ff1d1f0 to 51f9281 Compare January 27, 2026 09:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: secretmanager Issues related to the Secret Manager API. samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant