Skip to content

Conversation

iontzialla
Copy link

One sample for encapsulation and one for decapsulation. Also, updating the KMS Client version to the latest one (previous ones don't have support for these new APIs).

Description

Fixes #

Note: Before submitting a pull request, please open an issue for discussion if you are not associated with Google.

Checklist

  • I have followed Contributing Guidelines from CONTRIBUTING.MD
  • Tests pass: go test -v ./.. (see Testing)
  • Code formatted: gofmt (see Formatting)
  • Vetting pass: go vet (see Formatting)
  • These samples need a new API enabled in testing projects to pass (let us know which ones)
  • These samples need a new/updated env vars in testing projects set to pass (let us know which ones)
  • This sample adds a new sample directory, and I updated the CODEOWNERS file with the codeowners for this sample
  • This sample adds a new Product API, and I updated the Blunderbuss issue/PR auto-assigner with the codeowners for this sample
  • Please merge this PR for me once it is approved

@iontzialla iontzialla requested review from a team as code owners September 29, 2025 21:47
Copy link

snippet-bot bot commented Sep 29, 2025

Here is the summary of changes.

You are about to add 2 region tags.

This comment is generated by snippet-bot.
If you find problems with this result, please file an issue at:
https://github.com/googleapis/repo-automation-bots/issues.
To update this comment, add snippet-bot:force-run label or use the checkbox below:

  • Refresh this comment

@product-auto-label product-auto-label bot added api: cloudkms Issues related to the Cloud Key Management Service API. samples Issues that are directly related to samples. labels Sep 29, 2025
Copy link
Contributor

Summary of Changes

Hello @iontzialla, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request introduces practical Go code samples demonstrating the use of Key Encapsulation Mechanisms (KEMs) with Google Cloud KMS. It provides examples for both the encapsulation of a shared secret using a public key from KMS and the subsequent decapsulation of the resulting ciphertext using a corresponding private key managed by KMS. This enhancement allows developers to integrate post-quantum cryptography features more easily, supported by an essential update to the underlying KMS client library.

Highlights

  • KMS KEM Samples: New code samples have been added for Key Encapsulation Mechanisms (KEMs) in Google Cloud KMS.
  • Encapsulation & Decapsulation: Specifically, samples for encapsulating a shared secret using an ML-KEM-768 public key and decapsulating ciphertext using a KMS private key are included.
  • KMS Client Update: The Google Cloud KMS Go client library has been updated to its latest version to support these new KEM APIs.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces useful code samples for Key Encapsulation Mechanisms (KEMs) in Cloud KMS. The implementation is solid, but I've identified a few areas for improvement to enhance code quality, efficiency, and correctness. My feedback includes suggestions to address code duplication and inefficiency in CRC32C calculations, clarify misleading error messages in data integrity checks, and handle cryptographic outputs more safely. These changes will make the samples more robust and maintainable.

One sample for encapsulation and one for decapsulation.
Also, updating the KMS Client version to the latest one (previous ones don't have support for these new APIs).
@briandorsey briandorsey added the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Oct 1, 2025
@kokoro-team kokoro-team removed the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Oct 1, 2025
@briandorsey briandorsey self-assigned this Oct 1, 2025
@briandorsey briandorsey added the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Oct 2, 2025
@kokoro-team kokoro-team removed the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Oct 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
api: cloudkms Issues related to the Cloud Key Management Service API. samples Issues that are directly related to samples.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants