Repository navigation
Add Support for Regionally-Scoped Secrets for Google Cloud Secrets Manager Backend #49709
Description
Activity
- addedkind:featureFeature RequestsFeature Requestsneeds-triagelabel for new issues that we didn't triage yetlabel for new issues that we didn't triage yet
on Apr 24, 2025 - addedprovider:googleGoogle (including GCP) related issuesGoogle (including GCP) related issues
on Apr 24, 2025 - added and removedneeds-triagelabel for new issues that we didn't triage yetlabel for new issues that we didn't triage yet
on Apr 24, 2025 @potiuk Could I give a try ?
go ahead
@harikrishna12524, just wanted to check in and see how things were going. Need anything from me?
Hi @jroachgolf84 ,
Do you need feature for sending via regional endpoint also ?
As I read the documentation, if we specify location of secret, the request might still go to generic region and get redirected. So, we have to specify regional endpoint if we need to request to directly access the secret via regional endpoint.
This link has regions where we can store secrets and whether it supports regional endpoint or not.
https://cloud.google.com/secret-manager/docs/locations.I was trying to provide fix, but my laptop was not proper, so I couldn't get started. I got it fixed yesterday 😃.
Yes! We'll need to support the regional endpoint as well. Do you have a PR open?
@harikrishna12524, just wanted to check in on this one. Were you able to create a PR?
@jroachgolf84 I have completed the changes for regional endpoint and location_id in APIs. Just working on those tests. I think I will create a PR within weekend.
Sounds great, let me know if you need anything from me!
@potiuk, can you please re-open this issue, I didn't mean to close it.
Description
This feature will provide support for using regionally-scoped secrets stored in Google Secrets Manager.
Use case/motivation
The existing
airflow.providers.google.cloud.secrets.secret_manager.CloudSecretManagerBackenddoes not support regionally-scoped Secrets, which is something that is becoming more and more popular for teams leveraging GCP. This prevents teams storing credentials regionally from using an out-of-the-box Secrets Backend.Related issues
No related issues.
Are you willing to submit a PR?
Code of Conduct