class

Pyrite::Providers::GCPKMS

Inherits Pyrite::Provider < Reference < Object

Provider for Google Cloud Run, Google Kubernetes Engine (GKE), and Google Compute Engine (GCE).

Authenticates via the ambient GCP Metadata Server (169.254.169.254) to obtain an OIDC / OAuth2 access token for the default attached Service Account, and calls the Google Cloud KMS REST API (https://cloudkms.googleapis.com/v1/{KMS_RESOURCE}:decrypt) to unseal the payload.

Prerequisites

  • Google Cloud Service Account with roles/cloudkms.cryptoKeyDecrypter on the target key.
  • Environment variable $KMS_KEY_RESOURCE in format: projects/{project}/locations/{location}/keyRings/{keyRing}/cryptoKeys/{cryptoKey}

Example

provider = Pyrite::Providers::GCPKMS.new("projects/my-prod/locations/global/keyRings/ring/cryptoKeys/app-key")
config = Pyrite.bootstrap!(AppConfig, provider: provider)

Constants

METADATA_HOST = "metadata.google.internal"

Hostname of the Google Compute Engine metadata server

METADATA_PATH = "/computeMetadata/v1/instance/service-accounts/default/token"

API path for default service account access token retrieval

Constructors

new(kms_resource_name : String = ENV.fetch("KMS_KEY_RESOURCE", ""))

Initializes the provider with a KMS Key Resource name (defaults to $KMS_KEY_RESOURCE).

Source

Instance methods

kms_resource_name

Full Google Cloud KMS CryptoKey resource path

Source
name

Human-readable provider name

Source
unwrap(envelope_path : String) : String

Unwraps the Cloud KMS sealed envelope at envelope_path.

Source