Skip to content

[#12131] feat(gcp): Add Cloud KMS key inspection#12136

Open
nevzheng wants to merge 5 commits into
apache:mainfrom
nevzheng:codex/kms-api-05-gcp
Open

[#12131] feat(gcp): Add Cloud KMS key inspection#12136
nevzheng wants to merge 5 commits into
apache:mainfrom
nevzheng:codex/kms-api-05-gcp

Conversation

@nevzheng

@nevzheng nevzheng commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator

What changes were proposed in this pull request?

Add a Google Cloud KMS provider using the official SDK and Application Default Credentials. It accepts full CryptoKey resource names, restricts them to the configured project and location, and normalizes key presence, primary-version state, and ENCRYPT_DECRYPT purpose.

Why are the changes needed?

Google Cloud uses provider-specific resource names and version semantics. The adapter validates those rules while exposing the common KMS key-property contract.

Part of #12131. Depends on #12135 in the review stack.

Does this PR introduce any user-facing change?

Yes. It adds the google-cloud-kms source type and its configuration properties.

How was this patch tested?

  • ./gradlew :bundles:gcp:test -PskipITs

Series

@nevzheng

Copy link
Copy Markdown
Collaborator Author

Hi @roryqi and @asdf1234 — please review this KMS API change (5/11). Previous: #12135. Next: #12137. Epic: #12131.

@github-actions

Copy link
Copy Markdown

Code Coverage Report

Overall Project 68.01% +0.11% 🟢
Files changed 77.44% 🟢

Module Coverage
aliyun 1.72% 🔴
api 48.25% +0.43% 🟢
authorization-common 85.96% 🟢
aws 51.64% +9.61% 🟢
azure 2.47% 🔴
catalog-common 9.92% 🔴
catalog-fileset 79.74% 🟢
catalog-glue 66.91% 🟢
catalog-hive 79.4% 🟢
catalog-jdbc-common 45.7% 🟢
catalog-jdbc-doris 81.72% 🟢
catalog-jdbc-mysql 79.33% 🟢
catalog-jdbc-postgresql 83.39% 🟢
catalog-jdbc-starrocks 79.16% 🟢
catalog-kafka 77.01% 🟢
catalog-lakehouse-generic 59.18% 🟢
catalog-lakehouse-hudi 79.1% 🟢
catalog-lakehouse-iceberg 85.93% 🟢
catalog-lakehouse-paimon 84.23% 🟢
catalog-model 77.72% 🟢
cli 44.5% 🟢
client-java 78.27% 🟢
common 51.95% 🟢
core 82.67% -0.41% 🟢
filesystem-hadoop3 77.28% 🟢
flink 0.0% 🔴
flink-common 47.09% 🟢
flink-runtime 0.0% 🔴
gcp 47.02% +32.9% 🟢
hadoop-auth 68.0% 🟢
hadoop-common 12.7% 🔴
hive-metastore-common 53.4% 🟢
iceberg-common 64.65% 🟢
iceberg-rest-server 74.96% 🟢
idp-basic 86.02% 🟢
integration-test-common 0.0% 🔴
jobs 66.17% 🟢
lance-common 20.67% 🔴
lance-rest-server 64.84% 🟢
lineage 53.02% 🟢
optimizer 83.24% 🟢
optimizer-api 21.95% 🔴
server 85.92% 🟢
server-common 76.12% 🟢
spark 28.57% 🔴
spark-common 46.01% 🟢
tencent 69.84% 🟢
transit 90.75% 🟢
trino-connector 40.29% 🟢
Files
Module File Coverage
api KmsApi.java 100.0% 🟢
KmsClient.java 100.0% 🟢
KmsReference.java 100.0% 🟢
KmsAuthenticationException.java 0.0% 🔴
KmsClientFactory.java 0.0% 🔴
KmsConfigurationException.java 0.0% 🔴
KmsKeyProperties.java 0.0% 🔴
aws AwsKmsClient.java 100.0% 🟢
AwsKmsKeyProperties.java 100.0% 🟢
AwsKmsClientFactory.java 93.33% 🟢
core KmsConfig.java 100.0% 🟢
KmsClientRegistry.java 98.88% 🟢
GravitinoEnv.java 20.93% 🔴
gcp GoogleCloudKmsKeyMetadata.java 100.0% 🟢
GoogleCloudKmsKeyProperties.java 100.0% 🟢
GoogleCloudKmsSdkMetadataService.java 100.0% 🟢
GoogleCloudKmsClient.java 95.56% 🟢
GoogleCloudKmsClientFactory.java 85.29% 🟢
GoogleCloudKmsMetadataService.java 0.0% 🔴
transit OpenBaoTransitKmsKeyProperties.java 100.0% 🟢
TransitKeyData.java 100.0% 🟢
TransitReadKeyResponse.java 100.0% 🟢
VaultTransitKmsKeyProperties.java 100.0% 🟢
OpenBaoTransitKmsClient.java 97.3% 🟢
OpenBaoTransitKmsClientFactory.java 91.23% 🟢
VaultTransitKmsClientFactory.java 91.23% 🟢
TransitApiClient.java 90.22% 🟢
TransitReadKeyRequest.java 83.33% 🟢
VaultTransitKmsClient.java 82.35% 🟢
FileTokenSupplier.java 81.48% 🟢

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant