feat(storage): add support for encryption enforcement configurations#8937
Open
thiyaguk09 wants to merge 2 commits intogoogleapis:mainfrom
Open
feat(storage): add support for encryption enforcement configurations#8937thiyaguk09 wants to merge 2 commits intogoogleapis:mainfrom
thiyaguk09 wants to merge 2 commits intogoogleapis:mainfrom
Conversation
Adds metadata support for `customerManagedEncryptionEnforcementConfig` and `customerSuppliedEncryptionEnforcementConfig` to the Bucket resource. Includes: - Unit tests in BucketTest and StorageClientTest for metadata mapping. - System tests in KmsTest verifying FullyRestricted enforcement and 412 error handling.
Improving the robustness of the tests
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request enhances Google Cloud Storage bucket capabilities by introducing support for encryption enforcement configurations. It allows users to define and manage policies for Google-managed, customer-managed (KMS), and customer-supplied encryption keys, ensuring that objects stored in a bucket adhere to specified encryption requirements. The changes include updates to the API definitions, client libraries, and comprehensive test coverage to validate the new functionality.
Highlights
customerManagedEncryptionEnforcementConfigandcustomerSuppliedEncryptionEnforcementConfigto theBucketresource, allowing for stricter control over encryption policies.BucketTestandStorageClientTestto verify the correct mapping and handling of the new encryption enforcement metadata.KmsTestto validateFullyRestrictedenforcement and ensure proper 412 error handling when encryption policies are violated.