Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions secretmanager/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@
<groupId>com.google.cloud</groupId>
<scope>import</scope>
<type>pom</type>
<version>26.62.0</version>
<version>26.89.0</version>
</dependency>
</dependencies>
</dependencyManagement>
Expand All @@ -54,12 +54,12 @@
<dependency>
<groupId>com.google.cloud</groupId>
<artifactId>google-cloud-secretmanager</artifactId>
<version>2.66.0</version>
<version>2.98.0</version>
</dependency>
<dependency>
<groupId>com.google.api.grpc</groupId>
<artifactId>proto-google-cloud-secretmanager-v1</artifactId>
<version>2.66.0</version>
<version>2.98.0</version>
</dependency>
<dependency>
<groupId>com.google.cloud</groupId>
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
/*
* Copyright 2026 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package secretmanager;

// [START secretmanager_create_secret_with_type]
import com.google.cloud.secretmanager.v1.ProjectName;
import com.google.cloud.secretmanager.v1.Replication;
import com.google.cloud.secretmanager.v1.Secret;
import com.google.cloud.secretmanager.v1.Secret.SecretType;
import com.google.cloud.secretmanager.v1.SecretManagerServiceClient;
import java.io.IOException;

public class CreateSecretWithType {

public static void main(String[] args) throws IOException {
// TODO(developer): Replace these variables before running the sample.

// Your GCP project ID.
String projectId = "your-project-id";
// Resource ID of the secret to create.
String secretId = "your-secret-id";
// Secret type restriction, e.g. ACCESS_KEY, CERTIFICATE, OTHER_DB_CREDENTIALS, or OTHER.
// Use CLOUD_SQL_DB_CREDENTIALS only for a secret that will go through
// enableManagedRotation, which additionally requires a regional secret; see
// CreateRegionalSecretWithCloudSqlCredentials in the regionalsamples package.
SecretType secretType = SecretType.ACCESS_KEY;
createSecretWithType(projectId, secretId, secretType);
}

// Create a new secret with the given secret type restriction. Unlike
// CLOUD_SQL_DB_CREDENTIALS, these other secret types are plain metadata tags: they don't
// require any additional credentials payload at creation time.
public static Secret createSecretWithType(
String projectId, String secretId, SecretType secretType) throws IOException {
// Initialize the client that will be used to send requests. This client only needs to be
// created once, and can be reused for multiple requests.
try (SecretManagerServiceClient client = SecretManagerServiceClient.create()) {
// Build the parent name from the project.
ProjectName projectName = ProjectName.of(projectId);

// Build the secret to create, with the given secret type restriction.
Secret secret =
Secret.newBuilder()
.setReplication(
Replication.newBuilder()
.setAutomatic(Replication.Automatic.newBuilder().build())
.build())
.setSecretType(secretType)
.build();

// Create the secret.
Secret createdSecret = client.createSecret(projectName, secretId, secret);
System.out.printf("Created secret with secret type: %s\n", createdSecret.getName());

return createdSecret;
}
}
}
// [END secretmanager_create_secret_with_type]
57 changes: 57 additions & 0 deletions secretmanager/src/main/java/secretmanager/GetSecretType.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
/*
* Copyright 2026 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package secretmanager;

// [START secretmanager_get_secret_type]
import com.google.cloud.secretmanager.v1.Secret;
import com.google.cloud.secretmanager.v1.SecretManagerServiceClient;
import com.google.cloud.secretmanager.v1.SecretName;
import java.io.IOException;

public class GetSecretType {

public static void main(String[] args) throws IOException {
// TODO(developer): Replace these variables before running the sample.

// Your GCP project ID.
String projectId = "your-project-id";
// Resource ID of the secret you want to inspect.
String secretId = "your-secret-id";
getSecretType(projectId, secretId);
}

// Get and print the secret type (e.g. CLOUD_SQL_DB_CREDENTIALS, ACCESS_KEY, CERTIFICATE,
// OTHER_DB_CREDENTIALS, OTHER, or SECRET_TYPE_UNSPECIFIED for a secret with no type
// restriction) of the given secret.
public static Secret getSecretType(String projectId, String secretId) throws IOException {
// Initialize the client that will be used to send requests. This client only needs to be
// created once, and can be reused for multiple requests.
try (SecretManagerServiceClient client = SecretManagerServiceClient.create()) {
// Build the name.
SecretName secretName = SecretName.of(projectId, secretId);

// Get the secret.
Secret secret = client.getSecret(secretName);

System.out.printf(
"Found secret %s with secret type %s\n", secret.getName(), secret.getSecretType());

return secret;
}
}
}
// [END secretmanager_get_secret_type]
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
/*
* Copyright 2026 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package secretmanager.regionalsamples;

// [START secretmanager_create_regional_secret_with_cloud_sql_credentials]
import com.google.cloud.secretmanager.v1.LocationName;
import com.google.cloud.secretmanager.v1.Secret;
import com.google.cloud.secretmanager.v1.Secret.SecretType;
import com.google.cloud.secretmanager.v1.SecretManagerServiceClient;
import com.google.cloud.secretmanager.v1.SecretManagerServiceSettings;
import java.io.IOException;

public class CreateRegionalSecretWithCloudSqlCredentials {

public static void main(String[] args) throws IOException {
// TODO(developer): Replace these variables before running the sample.

// Your GCP project ID.
String projectId = "your-project-id";
// Location of the secret; must match the Cloud SQL instance's region.
String locationId = "your-location-id";
// Resource ID of the secret to create.
String secretId = "your-secret-id";
createRegionalSecretWithCloudSqlCredentials(projectId, locationId, secretId);
}

// Create a new secret with the Cloud SQL DB credentials secret type. This type is required
// to enable Secret Manager's automatic rotation of Cloud SQL passwords. It can only be set
// when the secret is created, and the secret's location must match the region of the target
// Cloud SQL instance.
public static Secret createRegionalSecretWithCloudSqlCredentials(
String projectId, String locationId, String secretId) throws IOException {

// Endpoint to call the regional secret manager sever
String apiEndpoint = String.format("secretmanager.%s.rep.googleapis.com:443", locationId);
SecretManagerServiceSettings secretManagerServiceSettings =
SecretManagerServiceSettings.newBuilder().setEndpoint(apiEndpoint).build();

// Initialize the client that will be used to send requests. This client only needs to be
// created once, and can be reused for multiple requests.
try (SecretManagerServiceClient client =
SecretManagerServiceClient.create(secretManagerServiceSettings)) {
// Build the parent name from the project.
LocationName location = LocationName.of(projectId, locationId);

// Build the secret to create, with the Cloud SQL DB credentials secret type.
Secret secret =
Secret.newBuilder().setSecretType(SecretType.CLOUD_SQL_DB_CREDENTIALS).build();

// Create the regional secret.
Secret createdSecret = client.createSecret(location.toString(), secretId, secret);
System.out.printf("Created secret: %s\n", createdSecret.getName());

// This built-in identity is what you grant Cloud SQL IAM permissions to, so that Secret
// Manager can rotate the database password on its behalf.
System.out.printf(
"Grant this identity Cloud SQL IAM permissions to enable rotation: %s\n",
createdSecret.getPolicyMember().getIamPolicyUidPrincipal());

return createdSecret;
}
}
}
// [END secretmanager_create_regional_secret_with_cloud_sql_credentials]
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
/*
* Copyright 2026 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package secretmanager.regionalsamples;

// [START secretmanager_enable_regional_secret_managed_rotation]
import com.google.cloud.secretmanager.v1.EnableManagedRotationRequest.CloudSQLSingleUserCredentials;
import com.google.cloud.secretmanager.v1.SecretManagerServiceClient;
import com.google.cloud.secretmanager.v1.SecretManagerServiceSettings;
import com.google.cloud.secretmanager.v1.SecretName;
import com.google.cloud.secretmanager.v1.SecretVersion;
import java.io.IOException;

public class EnableRegionalSecretManagedRotation {

public static void main(String[] args) throws IOException {
// TODO(developer): Replace these variables before running the sample.

// Your GCP project ID.
String projectId = "your-project-id";
// Location of the secret.
String locationId = "your-location-id";
// Resource ID of the Cloud SQL DB credentials secret to enable rotation on.
String secretId = "your-secret-id";
// Bare ID of the Cloud SQL instance (no project or region prefix).
String instanceId = "your-cloud-sql-instance-id";
// Username of the Cloud SQL database user.
String username = "your-cloud-sql-username";
enableRegionalSecretManagedRotation(projectId, locationId, secretId, instanceId, username);
}

// Enable managed rotation for a Cloud SQL DB credentials secret. This links the secret to a
// Cloud SQL instance and database user, and can only be called once per secret. It adds the
// secret's first version and sets the matching password on the Cloud SQL user, taking the
// place of a manually added secret version, which this secret type doesn't support.
// Afterwards, use rotateRegionalSecret to trigger further rotations.
//
// instanceId is the bare Cloud SQL instance ID (e.g. "my-instance") -- not a connection name.
// Neither the project nor the region should be included: passing "PROJECT_ID:INSTANCE_ID" (as
// gcloud's own `enable-managed-rotation --help` examples misleadingly show) or the full
// "PROJECT_ID:LOCATION_ID:INSTANCE_ID" connection name both fail -- the service already knows
// the project from the secret's own path, and prepends it internally, so a qualified value
// ends up double-prefixed.
public static SecretVersion enableRegionalSecretManagedRotation(
String projectId, String locationId, String secretId, String instanceId, String username)
throws IOException {

// Endpoint to call the regional secret manager sever
String apiEndpoint = String.format("secretmanager.%s.rep.googleapis.com:443", locationId);
SecretManagerServiceSettings secretManagerServiceSettings =
SecretManagerServiceSettings.newBuilder().setEndpoint(apiEndpoint).build();

// Initialize the client that will be used to send requests. This client only needs to be
// created once, and can be reused for multiple requests.
try (SecretManagerServiceClient client =
SecretManagerServiceClient.create(secretManagerServiceSettings)) {
// Despite the field name, the request's "parent" holds the full secret resource name, not
// a collection parent.
SecretName secretName =
SecretName.ofProjectLocationSecretName(projectId, locationId, secretId);

// Build the Cloud SQL credentials. Leaving the password unset lets Secret Manager
// generate a secure password itself.
CloudSQLSingleUserCredentials cloudSqlCredentials =
CloudSQLSingleUserCredentials.newBuilder()
.setInstanceId(instanceId)
.setUsername(username)
.build();

// Enable managed rotation.
SecretVersion version = client.enableManagedRotation(secretName, cloudSqlCredentials);
System.out.printf(
"Enabled managed rotation, created secret version: %s\n", version.getName());

return version;
}
}
}
// [END secretmanager_enable_regional_secret_managed_rotation]
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
/*
* Copyright 2026 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package secretmanager.regionalsamples;

// [START secretmanager_get_regional_secret_type]
import com.google.cloud.secretmanager.v1.Secret;
import com.google.cloud.secretmanager.v1.SecretManagerServiceClient;
import com.google.cloud.secretmanager.v1.SecretManagerServiceSettings;
import com.google.cloud.secretmanager.v1.SecretName;
import java.io.IOException;

public class GetRegionalSecretType {

public static void main(String[] args) throws IOException {
// TODO(developer): Replace these variables before running the sample.

// Your GCP project ID.
String projectId = "your-project-id";
// Location of the secret.
String locationId = "your-location-id";
// Resource ID of the secret you want to inspect.
String secretId = "your-secret-id";
getRegionalSecretType(projectId, locationId, secretId);
}

// Get and print the secret type (e.g. CLOUD_SQL_DB_CREDENTIALS, ACCESS_KEY, CERTIFICATE,
// OTHER_DB_CREDENTIALS, OTHER, or SECRET_TYPE_UNSPECIFIED for a secret with no type
// restriction) of the given secret.
public static Secret getRegionalSecretType(String projectId, String locationId, String secretId)
throws IOException {

// Endpoint to call the regional secret manager sever
String apiEndpoint = String.format("secretmanager.%s.rep.googleapis.com:443", locationId);
SecretManagerServiceSettings secretManagerServiceSettings =
SecretManagerServiceSettings.newBuilder().setEndpoint(apiEndpoint).build();

// Initialize the client that will be used to send requests. This client only needs to be
// created once, and can be reused for multiple requests.
try (SecretManagerServiceClient client =
SecretManagerServiceClient.create(secretManagerServiceSettings)) {
// Build the name.
SecretName secretName =
SecretName.ofProjectLocationSecretName(projectId, locationId, secretId);

// Get the secret.
Secret secret = client.getSecret(secretName);

System.out.printf(
"Found regional secret %s with secret type %s\n",
secret.getName(), secret.getSecretType());

return secret;
}
}
}
// [END secretmanager_get_regional_secret_type]
Loading
Loading