Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions secretmanager/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ This simple command-line application demonstrates how to invoke
- GOOGLE_CLOUD_PUBSUB_TOPIC - Full name of topic (projects/{project}/topics/{topic}).
- GOOGLE_CLOUD_KMS_KEY - Full name of global KMS key (projects/{project}/locations/global/keyRings/{keyring}/cryptoKeys/{key}).
- GOOGLE_CLOUD_REGIONAL_KMS_KEY - Full name of regional KMS key (projects/{project}/locations/{location}/keyRings/{keyring}/cryptoKeys/{key}).
- CLOUD_SQL_INSTANCE / CLOUD_SQL_USER - Bare Cloud SQL instance ID and database username, required by the Cloud SQL managed-rotation tests.

1. **Download The Credentials** - Click "Go to credentials" after enabling the
APIs. Click "New Credentials" and select "Service Account Key". Create a new
Expand Down
2 changes: 1 addition & 1 deletion secretmanager/composer.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"require": {
"google/cloud-secret-manager": "^2.1.0",
"google/cloud-secret-manager": "^2.4.0",
"google/cloud-resource-manager": "^1.0"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
<?php
/*
* Copyright 2026 Google LLC.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

/*
* For instructions on how to run the full sample:
*
* @see https://github.com/GoogleCloudPlatform/php-docs-samples/tree/main/secretmanager/README.md
*/

declare(strict_types=1);

namespace Google\Cloud\Samples\SecretManager;

// [START secretmanager_create_regional_secret_with_cloud_sql_credentials]
use Google\Cloud\SecretManager\V1\CreateSecretRequest;
use Google\Cloud\SecretManager\V1\Secret;
use Google\Cloud\SecretManager\V1\Secret\SecretType;
use Google\Cloud\SecretManager\V1\Client\SecretManagerServiceClient;

/**
* Create a new secret with the Cloud SQL DB credentials secret type. This
* type is required to enable Secret Manager's automatic rotation of Cloud
* SQL passwords. It can only be set when the secret is created, and the
* secret's location must match the region of the target Cloud SQL instance.
*
* @param string $projectId Your Google Cloud Project ID (e.g. 'my-project')
* @param string $locationId Location of the secret; must match the Cloud SQL
* instance's region (e.g. 'us-central1')
* @param string $secretId Your secret ID (e.g. 'my-secret')
*/
function create_regional_secret_with_cloud_sql_credentials(string $projectId, string $locationId, string $secretId): void
{
// Specify regional endpoint.
$options = ['apiEndpoint' => "secretmanager.$locationId.rep.googleapis.com"];

// Create the Secret Manager client.
$client = new SecretManagerServiceClient($options);

// Build the resource name of the parent project.
$parent = $client->locationName($projectId, $locationId);

$secret = new Secret([
'secret_type' => SecretType::CLOUD_SQL_DB_CREDENTIALS,
]);

$request = CreateSecretRequest::build($parent, $secretId, $secret);

// Create the secret.
$newSecret = $client->createSecret($request);

printf('Created secret: %s%s', $newSecret->getName(), PHP_EOL);

// This built-in identity is what you grant Cloud SQL IAM permissions to,
// so that Secret Manager can rotate the database password on its behalf.
printf(
'Grant this identity Cloud SQL IAM permissions to enable rotation: %s%s',
$newSecret->getPolicyMember()->getIamPolicyUidPrincipal(),
PHP_EOL
);
}
// [END secretmanager_create_regional_secret_with_cloud_sql_credentials]

// The following 2 lines are only needed to execute the samples on the CLI
require_once __DIR__ . '/../../testing/sample_helpers.php';
\Google\Cloud\Samples\execute_sample(__FILE__, __NAMESPACE__, $argv);
78 changes: 78 additions & 0 deletions secretmanager/src/create_secret_with_type.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
<?php
/*
* Copyright 2026 Google LLC.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

/*
* For instructions on how to run the full sample:
*
* @see https://github.com/GoogleCloudPlatform/php-docs-samples/tree/main/secretmanager/README.md
*/

declare(strict_types=1);

namespace Google\Cloud\Samples\SecretManager;

// [START secretmanager_create_secret_with_type]
// Import the Secret Manager client library.
use Google\Cloud\SecretManager\V1\CreateSecretRequest;
use Google\Cloud\SecretManager\V1\Replication;
use Google\Cloud\SecretManager\V1\Replication\Automatic;
use Google\Cloud\SecretManager\V1\Secret;
use Google\Cloud\SecretManager\V1\Secret\SecretType;
use Google\Cloud\SecretManager\V1\Client\SecretManagerServiceClient;

/**
* Create a new secret with the given secret type restriction (e.g.
* ACCESS_KEY, CERTIFICATE, OTHER_DB_CREDENTIALS, or OTHER -- use
* CLOUD_SQL_DB_CREDENTIALS only for a regional secret that will go through
* enable_regional_secret_managed_rotation.php). Unlike
* CLOUD_SQL_DB_CREDENTIALS, these other secret types are plain metadata
* tags: they don't require any additional credentials payload at creation
* time.
*
* @param string $projectId Your Google Cloud Project ID (e.g. 'my-project')
* @param string $secretId Your secret ID (e.g. 'my-secret')
* @param string $secretType Secret type restriction to apply (e.g. 'ACCESS_KEY', 'CERTIFICATE', 'OTHER_DB_CREDENTIALS', 'OTHER')
*/
function create_secret_with_type(string $projectId, string $secretId, string $secretType): void
{
// Create the Secret Manager client.
$client = new SecretManagerServiceClient();

// Build the resource name of the parent project.
$parent = $client->projectName($projectId);

$secret = new Secret([
'replication' => new Replication([
'automatic' => new Automatic(),
]),
'secret_type' => SecretType::value($secretType),
]);

// Build the request.
$request = CreateSecretRequest::build($parent, $secretId, $secret);

// Create the secret, with the given secret type restriction.
$newSecret = $client->createSecret($request);

// Print the new secret name.
printf('Created secret with secret type: %s%s', $newSecret->getName(), PHP_EOL);
}
// [END secretmanager_create_secret_with_type]

// The following 2 lines are only needed to execute the samples on the CLI
require_once __DIR__ . '/../../testing/sample_helpers.php';
\Google\Cloud\Samples\execute_sample(__FILE__, __NAMESPACE__, $argv);
86 changes: 86 additions & 0 deletions secretmanager/src/enable_regional_secret_managed_rotation.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
<?php
/*
* Copyright 2026 Google LLC.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

/*
* For instructions on how to run the full sample:
*
* @see https://github.com/GoogleCloudPlatform/php-docs-samples/tree/main/secretmanager/README.md
*/

declare(strict_types=1);

namespace Google\Cloud\Samples\SecretManager;

// [START secretmanager_enable_regional_secret_managed_rotation]
use Google\Cloud\SecretManager\V1\EnableManagedRotationRequest;
use Google\Cloud\SecretManager\V1\EnableManagedRotationRequest\CloudSQLSingleUserCredentials;
use Google\Cloud\SecretManager\V1\Client\SecretManagerServiceClient;

/**
* Enable managed rotation for a Cloud SQL DB credentials secret. This links
* the secret to a Cloud SQL instance and database user, and can only be
* called once per secret. It adds the secret's first version and sets the
* matching password on the Cloud SQL user, taking the place of a manually
* added secret version, which this secret type doesn't support. Afterwards,
* use rotate_regional_secret.php to trigger further rotations.
*
* $instanceId is the bare Cloud SQL instance ID (e.g. "my-instance") -- not a
* connection name. Neither the project nor the region should be included:
* passing "PROJECT_ID:INSTANCE_ID" (as gcloud's own
* `enable-managed-rotation --help` examples misleadingly show) or the full
* "PROJECT_ID:LOCATION_ID:INSTANCE_ID" connection name both fail -- the
* service already knows the project from the secret's own path, and prepends
* it internally, so a qualified value ends up double-prefixed.
*
* @param string $projectId Your Google Cloud Project ID (e.g. 'my-project')
* @param string $locationId Location of the secret (e.g. 'us-central1')
* @param string $secretId ID of the Cloud SQL DB credentials secret to enable rotation on
* @param string $instanceId Bare ID of the Cloud SQL instance (no project or region prefix)
* @param string $username Username of the Cloud SQL database user
*/
function enable_regional_secret_managed_rotation(string $projectId, string $locationId, string $secretId, string $instanceId, string $username): void
{
// Specify regional endpoint.
$options = ['apiEndpoint' => "secretmanager.$locationId.rep.googleapis.com"];

// Create the Secret Manager client.
$client = new SecretManagerServiceClient($options);

// Build the resource name of the secret.
$parent = $client->projectLocationSecretName($projectId, $locationId, $secretId);

$credentials = new CloudSQLSingleUserCredentials([
'instance_id' => $instanceId,
'username' => $username,
// Leaving password unset lets Secret Manager generate a secure
// password itself.
]);

$request = (new EnableManagedRotationRequest())
->setParent($parent)
->setCloudSqlSingleUserCredentials($credentials);

// Enable managed rotation.
$version = $client->enableManagedRotation($request);

printf('Enabled managed rotation, created secret version: %s%s', $version->getName(), PHP_EOL);
}
// [END secretmanager_enable_regional_secret_managed_rotation]

// The following 2 lines are only needed to execute the samples on the CLI
require_once __DIR__ . '/../../testing/sample_helpers.php';
\Google\Cloud\Samples\execute_sample(__FILE__, __NAMESPACE__, $argv);
71 changes: 71 additions & 0 deletions secretmanager/src/get_regional_secret_type.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
<?php
/*
* Copyright 2026 Google LLC.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

/*
* For instructions on how to run the full sample:
*
* @see https://github.com/GoogleCloudPlatform/php-docs-samples/tree/main/secretmanager/README.md
*/

declare(strict_types=1);

namespace Google\Cloud\Samples\SecretManager;

// [START secretmanager_get_regional_secret_type]
// Import the Secret Manager client library.
use Google\Cloud\SecretManager\V1\Client\SecretManagerServiceClient;
use Google\Cloud\SecretManager\V1\GetSecretRequest;
use Google\Cloud\SecretManager\V1\Secret\SecretType;

/**
* Get and print the secret type (e.g. CLOUD_SQL_DB_CREDENTIALS, ACCESS_KEY,
* CERTIFICATE, OTHER_DB_CREDENTIALS, OTHER, or SECRET_TYPE_UNSPECIFIED for a
* secret with no type restriction) of the given regional secret.
*
* @param string $projectId Your Google Cloud Project ID (e.g. 'my-project')
* @param string $locationId Location of the secret (e.g. 'us-central1')
* @param string $secretId Your secret ID (e.g. 'my-secret')
*/
function get_regional_secret_type(string $projectId, string $locationId, string $secretId): void
{
// Specify regional endpoint.
$options = ['apiEndpoint' => "secretmanager.$locationId.rep.googleapis.com"];

// Create the Secret Manager client.
$client = new SecretManagerServiceClient($options);

// Build the resource name of the secret.
$name = $client->projectLocationSecretName($projectId, $locationId, $secretId);

// Build the request.
$request = GetSecretRequest::build($name);

// Get the secret.
$secret = $client->getSecret($request);

printf(
'Found regional secret %s with secret type %s%s',
$secret->getName(),
SecretType::name($secret->getSecretType()),
PHP_EOL
);
}
// [END secretmanager_get_regional_secret_type]

// The following 2 lines are only needed to execute the samples on the CLI
require_once __DIR__ . '/../../testing/sample_helpers.php';
\Google\Cloud\Samples\execute_sample(__FILE__, __NAMESPACE__, $argv);
Loading
Loading