Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
52 commits
Select commit Hold shift + click to select a range
0e0f1e4
created a new provider
XuechunHou Apr 16, 2025
6dcd5c2
Merge remote-tracking branch 'upstream/main' into google-secret-provider
XuechunHou Apr 25, 2025
3a72bf7
google secret provider implementation
XuechunHou Apr 28, 2025
dca1219
Merge remote-tracking branch 'upstream/main' into google-secret-provider
XuechunHou Apr 28, 2025
978a03d
cast error to apiError before returning to caller
XuechunHou Apr 28, 2025
427a943
updated secret provider impl, and ran auto generation tool
XuechunHou Apr 30, 2025
6b3bb42
Merge remote-tracking branch 'upstream/main' into google-secret-provider
XuechunHou Apr 30, 2025
e6e2e63
updated codeowner and added the changelog
XuechunHou Apr 30, 2025
667b3f1
Merge pull request #1 from XuechunHou/google-secret-provider
XuechunHou Apr 30, 2025
72d62dc
removed ineligible code owners
XuechunHou Apr 30, 2025
f37580d
changed the code owner to the author of this provider
XuechunHou Apr 30, 2025
3065fca
fixed extra : in error msg
XuechunHou Apr 30, 2025
17b6d0f
Merge remote-tracking branch 'upstream/main'
XuechunHou May 3, 2025
5deede8
renamed the provider from googlesecretsprovider to googlesecretmanage…
XuechunHou May 3, 2025
793cea5
updated wording in the readme file.
XuechunHou May 3, 2025
2ba11df
updated readme to mention ADC
XuechunHou May 3, 2025
c3c2e09
renamed directory
XuechunHou May 3, 2025
7ca7813
addressed comments in tests
XuechunHou May 5, 2025
666b4f5
Merge remote-tracking branch 'upstream/main'
XuechunHou May 5, 2025
a0fb2aa
updated code owner to XuechunHou
XuechunHou May 5, 2025
f8db4b1
close secret manager client in Shutdown, so that the network conencti…
XuechunHou May 5, 2025
ee31d6c
unlock regardless of secret manager client being nil or non-nil in th…
XuechunHou May 5, 2025
9a9a372
fixed test function name
XuechunHou May 5, 2025
ee136df
resolved comments
XuechunHou May 5, 2025
251fdad
resolved comments
XuechunHou May 6, 2025
03e5cba
does not reset provider.client to nil
XuechunHou May 6, 2025
03bb82f
resolved comments
XuechunHou May 6, 2025
80df598
un-export mockSecretsManagerClient
XuechunHou May 6, 2025
3a55f0f
removed thread safe implementation
XuechunHou May 6, 2025
3d976e9
removed codeowner
XuechunHou May 6, 2025
75d36a4
added braydon as code owner
XuechunHou May 6, 2025
e803f6a
removed unit test
XuechunHou May 6, 2025
b179c11
updated codeowner
XuechunHou May 6, 2025
940ac69
Merge branch 'open-telemetry:main' into main
XuechunHou May 6, 2025
0681cc1
trying to fix codeowner workflow
XuechunHou May 6, 2025
158ab54
fixing codeowner workflow
XuechunHou May 6, 2025
4cf7bf7
fixing the ordering in codeowner file
XuechunHou May 6, 2025
6ebfbf6
fixed component list ordering
XuechunHou May 6, 2025
200424e
Merge branch 'main' into main
XuechunHou May 6, 2025
d5dda73
updated go to 1.23 in go.mod
XuechunHou May 6, 2025
60398c8
Merge branch 'main' of github.com:XuechunHou/opentelemetry-collector-…
XuechunHou May 6, 2025
261c016
fixed lint and formatting issue
XuechunHou May 6, 2025
4256877
ran make gotidy
XuechunHou May 6, 2025
09170e0
ran make tidylist
XuechunHou May 6, 2025
c63d67a
fixed lint error
XuechunHou May 6, 2025
81f13a7
ran make genlabels
XuechunHou May 6, 2025
3db0ace
ran make gencodecov
XuechunHou May 6, 2025
47780f9
Merge remote-tracking branch 'upstream/main'
XuechunHou May 6, 2025
c68c24b
Merge remote-tracking branch 'upstream/main'
XuechunHou May 6, 2025
427594e
Merge remote-tracking branch 'upstream/main'
XuechunHou May 7, 2025
ce21e07
Merge remote-tracking branch 'upstream/main'
XuechunHou May 7, 2025
35c4af3
Merge branch 'main' into main
braydonk May 7, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions .chloggen/google-secrets-manager-provider.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# One of 'breaking', 'deprecation', 'new_component', 'enhancement', 'bug_fix'
change_type: new_component

# The name of the component, or a single word describing the area of concern, (e.g. filelogreceiver)
component: confmap/googlesecretmanagerprovider

# A brief description of the change. Surround your text with quotes ("") if it needs to start with a backtick (`).
note: Initial implementation of secrets manager provider. Allows fetch secrets from Google Secrets Manager

# One or more tracking issues related to the change
issues: [39665]

# (Optional) One or more lines of additional information to render under the primary note.
# These lines will be padded with 2 spaces and then inserted directly into the document.
# Use pipe (|) for multiline entries.
subtext:
4 changes: 4 additions & 0 deletions .codecov.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,10 @@ component_management:
name: confmap_provider_aesprovider
paths:
- confmap/provider/aesprovider/**
- component_id: confmap_provider_googlesecretmanagerprovider
name: confmap_provider_googlesecretmanagerprovider
paths:
- confmap/provider/googlesecretmanagerprovider/**
- component_id: confmap_provider_s3provider
name: confmap_provider_s3provider
paths:
Expand Down
1 change: 1 addition & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ cmd/otelcontribcol/ @open-telemetry
cmd/oteltestbedcol/ @open-telemetry/collector-contrib-approvers
cmd/telemetrygen/ @open-telemetry/collector-contrib-approvers @mx-psi @codeboten @Erog38
confmap/provider/aesprovider/ @open-telemetry/collector-contrib-approvers @djaglowski
confmap/provider/googlesecretmanagerprovider/ @open-telemetry/collector-contrib-approvers @aabmass @dashpole @jsuereth @psx95 @braydonk @ridwanmsharif
confmap/provider/s3provider/ @open-telemetry/collector-contrib-approvers @Aneurysm9
confmap/provider/secretsmanagerprovider/ @open-telemetry/collector-contrib-approvers @atoulme
connector/countconnector/ @open-telemetry/collector-contrib-approvers @djaglowski
Expand Down
1 change: 1 addition & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ body:
- cmd/oteltestbedcol
- cmd/telemetrygen
- confmap/provider/aesprovider
- confmap/provider/googlesecretmanagerprovider
- confmap/provider/s3provider
- confmap/provider/secretsmanagerprovider
- connector/count
Expand Down
1 change: 1 addition & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ body:
- cmd/oteltestbedcol
- cmd/telemetrygen
- confmap/provider/aesprovider
- confmap/provider/googlesecretmanagerprovider
- confmap/provider/s3provider
- confmap/provider/secretsmanagerprovider
- connector/count
Expand Down
1 change: 1 addition & 0 deletions .github/ISSUE_TEMPLATE/other.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ body:
- cmd/oteltestbedcol
- cmd/telemetrygen
- confmap/provider/aesprovider
- confmap/provider/googlesecretmanagerprovider
- confmap/provider/s3provider
- confmap/provider/secretsmanagerprovider
- connector/count
Expand Down
1 change: 1 addition & 0 deletions .github/ISSUE_TEMPLATE/unmaintained.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ body:
- cmd/oteltestbedcol
- cmd/telemetrygen
- confmap/provider/aesprovider
- confmap/provider/googlesecretmanagerprovider
- confmap/provider/s3provider
- confmap/provider/secretsmanagerprovider
- connector/count
Expand Down
1 change: 1 addition & 0 deletions .github/component_labels.txt
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ cmd/otelcontribcol cmd/otelcontribcol
cmd/oteltestbedcol cmd/oteltestbedcol
cmd/telemetrygen cmd/telemetrygen
confmap/provider/aesprovider confmap/provider/aesprovider
confmap/provider/googlesecretmanagerprovider confmap/provider/googlesecretmanagerprovider
confmap/provider/s3provider confmap/provider/s3provider
confmap/provider/secretsmanagerprovider confmap/provider/secretsmanagerprovider
connector/countconnector connector/count
Expand Down
1 change: 1 addition & 0 deletions confmap/provider/googlesecretmanagerprovider/Makefile
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
include ../../../Makefile.Common
61 changes: 61 additions & 0 deletions confmap/provider/googlesecretmanagerprovider/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# Google Secrets Provider
<!-- status autogenerated section -->
| Status | |
| ------------- |-----------|
| Stability | [development] |
| Distributions | [] |
| Issues | [![Open issues](https://img.shields.io/github/issues-search/open-telemetry/opentelemetry-collector-contrib?query=is%3Aissue%20is%3Aopen%20label%3Aprovider%2Fgooglesecretmanagerprovider%20&label=open&color=orange&logo=opentelemetry)](https://github.com/open-telemetry/opentelemetry-collector-contrib/issues?q=is%3Aopen+is%3Aissue+label%3Aprovider%2Fgooglesecretmanagerprovider) [![Closed issues](https://img.shields.io/github/issues-search/open-telemetry/opentelemetry-collector-contrib?query=is%3Aissue%20is%3Aclosed%20label%3Aprovider%2Fgooglesecretmanagerprovider%20&label=closed&color=blue&logo=opentelemetry)](https://github.com/open-telemetry/opentelemetry-collector-contrib/issues?q=is%3Aclosed+is%3Aissue+label%3Aprovider%2Fgooglesecretmanagerprovider) |
| Code coverage | [![codecov](https://codecov.io/github/open-telemetry/opentelemetry-collector-contrib/graph/main/badge.svg?component=provider_googlesecretmanagerprovider)](https://app.codecov.io/gh/open-telemetry/opentelemetry-collector-contrib/tree/main/?components%5B0%5D=provider_googlesecretmanagerprovider&displayType=list) |
| [Code Owners](https://github.com/open-telemetry/opentelemetry-collector-contrib/blob/main/CONTRIBUTING.md#becoming-a-code-owner) | [@aabmass](https://www.github.com/aabmass), [@dashpole](https://www.github.com/dashpole), [@jsuereth](https://www.github.com/jsuereth), [@psx95](https://www.github.com/psx95), [@braydonk](https://www.github.com/braydonk), [@ridwanmsharif](https://www.github.com/ridwanmsharif) |

[development]: https://github.com/open-telemetry/opentelemetry-collector/blob/main/docs/component-stability.md#development
<!-- end autogenerated section -->

## Summary

This Provider component offers a secure way to reference secrets or sensitive information in collector configurations using [Google Secret Manager](https://cloud.google.com/security/products/secret-manager). Use a placeholder in the format `${googlesecretmanagerprovider:projects/<project Id>/secrets/<secret Id>/versions/<version Id>}` within your configuration. The actual secrets will then be fetched dynamically from [Google Secret Manager](https://cloud.google.com/security/products/secret-manager) during collector initialization.
## Usage

- Simply replace plaintext secrets within your collector configuration with the placeholder: `${googlesecretmanagerprovider:projects/<project Id>/secrets/<secret Id>/versions/<version Id>}`

An example collector configuration:

```
receivers:
otlp:
protocols:
grpc:
http:
processors:
batch:

exporters:
logging:
loglevel: debug
http:
endpoint: "https://example.com/api/metrics"
headers:
X-API-Key: ${googlesecretmanagerprovider:projects/12345/secrets/my-secret/versions/1}
service:
pipelines:
traces:
receivers: [otlp]
processors: [batch]
exporters: [logging, http]
metrics:
receivers: [otlp]
processors: [batch]
exporters: [logging, http]
logs:
receivers: [otlp]
processors: [batch]
exporters: [logging, http]

```

### Prerequisites
1. Make sure to enable access to the [Secret Manager API](https://cloud.google.com/secret-manager/docs/accessing-the-api).
2. Make sure to [add the secret entries to Google Secret Manager](https://cloud.google.com/secret-manager/docs/create-secret-quickstart) before referencing them in the collector configurations.
3. This Provider interacts with Google Secret Manager using the Secret Manager client library. This library uses [Application Default Credentials (ADC)](https://cloud.google.com/docs/authentication/application-default-credentials) to locate authentication credentials for Secret Manager. Therefore, if you run your collector in a local environment, execute the [`gcloud auth application-default login`](https://cloud.google.com/secret-manager/docs/authentication#client-libs) command to generate the necessary credential file to provide to ADC.
4. However, if your collector runs on Google Compute Engine (GCE) or Google Kubernetes Engine (GKE), running `gcloud auth application-default login` is optional. This is because ADC can retrieve credentials via [the metadata server](https://cloud.google.com/docs/authentication/application-default-credentials#order). However, ensure that your GKE or GCE instance [has enabled the cloud-platform OAuth scope](https://cloud.google.com/secret-manager/docs/accessing-the-api#oauth-scopes). Additionally, verify that the Service Account attached to the GCE or GKE instance has been granted at least the [roles/secretmanager.secretAccessor](https://cloud.google.com/secret-manager/docs/access-control#secret-manager-roles) IAM role to access secret entries in Google Secret Manager.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

57 changes: 57 additions & 0 deletions confmap/provider/googlesecretmanagerprovider/go.mod
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
module github.com/open-telemetry/opentelemetry-collector-contrib/confmap/provider/googlesecretmanagerprovider

go 1.23.0

require (
cloud.google.com/go/secretmanager v1.14.7
github.com/googleapis/gax-go/v2 v2.14.1
github.com/stretchr/testify v1.10.0
go.opentelemetry.io/collector/confmap v1.31.1-0.20250505152726-56c7da210783
go.uber.org/goleak v1.3.0
google.golang.org/grpc v1.71.1
)

require (
cloud.google.com/go/auth v0.16.0 // indirect
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
cloud.google.com/go/compute/metadata v0.6.0 // indirect
cloud.google.com/go/iam v1.5.0 // indirect
github.com/davecgh/go-spew v1.1.1 // indirect
github.com/felixge/httpsnoop v1.0.4 // indirect
github.com/go-logr/logr v1.4.2 // indirect
github.com/go-logr/stdr v1.2.2 // indirect
github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
github.com/gobwas/glob v0.2.3 // indirect
github.com/google/s2a-go v0.1.9 // indirect
github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
github.com/hashicorp/go-version v1.7.0 // indirect
github.com/knadh/koanf/maps v0.1.2 // indirect
github.com/knadh/koanf/providers/confmap v1.0.0 // indirect
github.com/knadh/koanf/v2 v2.2.0 // indirect
github.com/mitchellh/copystructure v1.2.0 // indirect
github.com/mitchellh/reflectwalk v1.0.2 // indirect
github.com/pmezard/go-difflib v1.0.0 // indirect
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
go.opentelemetry.io/collector/featuregate v1.31.1-0.20250505152726-56c7da210783 // indirect
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60.0 // indirect
go.opentelemetry.io/otel v1.35.0 // indirect
go.opentelemetry.io/otel/metric v1.35.0 // indirect
go.opentelemetry.io/otel/trace v1.35.0 // indirect
go.uber.org/multierr v1.11.0 // indirect
go.uber.org/zap v1.27.0 // indirect
golang.org/x/crypto v0.37.0 // indirect
golang.org/x/net v0.39.0 // indirect
golang.org/x/oauth2 v0.29.0 // indirect
golang.org/x/sync v0.13.0 // indirect
golang.org/x/sys v0.32.0 // indirect
golang.org/x/text v0.24.0 // indirect
golang.org/x/time v0.11.0 // indirect
google.golang.org/api v0.229.0 // indirect
google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20250414145226-207652e42e2e // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20250414145226-207652e42e2e // indirect
google.golang.org/protobuf v1.36.6 // indirect
gopkg.in/yaml.v3 v3.0.1 // indirect
sigs.k8s.io/yaml v1.4.0 // indirect
)
Loading
Loading