HEX
Server: Apache/2.4.68 (Debian)
System: Linux as-cs-widget-demo-us-central1 6.1.0-44-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.164-1 (2026-03-09) x86_64
User: root (0)
PHP: 8.2.32
Disabled: NONE
Upload Files
File: //lib/google-cloud-sdk/lib/surface/secrets/replication/__pycache__/update.cpython-312.pyc
�

��] ���dZddlmZddlmZddlmZddlmZddlm	Z	ddlm
Zddlm
Zddlm
Z
dd	lmZe	j"e	j$j&e	j$j(�Gd
�de	j*��Zy)
zUpdate an existing secret.�)�absolute_import)�division)�unicode_literals)�api)�base)�
exceptions)�args)�logc�V�eZdZdZdZdZdZdZdZdZ	dZ
d	Zd
Ze
d��Zd�Zd
�Zd�Zy)�Updatea�Update a secret replica's metadata.

      Update a secret replica's metadata (e.g. cmek policy). This command will
      return an error if given a secret that does not exist or if given a
      location that the given secret doesn't exist in.

      The --remove-kms-key flag is only valid for Secrets that have an
      automatic replication policy or exist in a single location. To remove
      keys from a Secret with multiple user managed replicas, please use the
      set-replication command.

      ## EXAMPLES

      To remove CMEK from a secret called 'my-secret', run:

        $ {command} my-secret --remove-cmek

      To set the CMEK key on an automatic secret called my-secret to a specified
      KMS key, run:

        ${command} my-secret
        --set-kms-key=projects/my-project/locations/global/keyRings/my-keyring/cryptoKeys/my-key

      To set the CMEK key on a secret called my-secret to a specified KMS key in
      a specified location in its replication, run:

        ${command} my-secret
        --set-kms-key=projects/my-project/locations/us-central1/keyRings/my-keyring/cryptoKeys/my-key
        --location=us-central1


  z9There are no changes to the secret [{secret}] for update.zxThe secret [{secret}] cannot be updated because it does not exist. Please use the create command to create a new secret.z�This secret has a user managed replication polciy. The location in which to set the customer managed encryption key must be set with --location.zxThere was a problem updating replication for this secret. Please use the replication set command to perform this update.zuThis secret has an automatic replication policy. To set its customer managed encryption key, please omit --locations.z4The secret does not have a replica in this location.z�Either all replicas must use customer managed encryption or all replicas must use Google managed encryption. To add customer managed encryption to all replicas, please use the replication set command.zGCannot simultaneously set and remove a customer managed encryption key.z�Cannot remove customer managed encryption keys for just one location. To use Google managed encryption keys for all locations, please remove --locations.c�`�tj|ddd��tj|�y)Nz	to updateT)�purpose�
positional�required)�secrets_args�	AddSecret�AddUpdateReplicationGroup)�parsers �)lib/surface/secrets/replication/update.py�ArgszUpdate.Args\s(��������t�E��*�*�6�2�c�,�tj|j��}|jjrMtj
|��j
|dgg�}tj
�j|�|S|jjr�|jjjr�g}|jjjD]H}|jstj|j��|j|j��Jtj
|��j
|d|g�}tj
�j|�|Stj|j��)N��api_version�	automatic�user-managed)�secrets_api�GetApiFromTrack�ReleaseTrack�replicationr�Secrets�SetReplication�secrets_log�UpdatedReplication�userManaged�replicas�locationr�MisconfiguredReplicationError�!MISCONFIGURED_REPLICATION_MESSAGE�append)�self�
secret_ref�secretr�updated_secret�	locations�replicas       r�_RemoveCmekzUpdate._RemoveCmekbsO���-�-�d�.?�.?�.A�B�K�
���#�#�"�*�*�!����z�;��B�7������.�.�z�:�
��
���%�%�&�*<�*<�*H�*H�*Q�*Q��i��'�'�3�3�<�<�'�����8�8��4�4�6�6�����)�)�*�	=�
#�*�*�!����z�>�9�b�A������.�.�z�:�
��
�
2�
2��.�.�0�0rc�J�tj|j��}|jjrp|r tjd|j��tj|��j|dg|g�}tj�j|�|S|jj�r�|jjj�r�|s tjd|j��g}g}d}	|jjjD]�}
|
j st#j$|j&��|j)|
j �||
j k(rd}	|j)|��l|
j*s�y|
j*j,s��|j)|
j*j,���|	s tj.d|j0��t3|�t3|�k7rt#j4|j6��tj|��j|d||�}tj�j|�|St#j$|j&��)Nr'rrFTr)rrrr r�calliope_exceptions�BadArgumentException�LOCATION_AND_AUTOMATIC_MESSAGEr!r"r#r$r%r&�RequiredArgumentException�LOCATION_REQUIRED_MESSAGEr'rr(r)r*�customerManagedEncryption�
kmsKeyName�InvalidArgumentException�LOCATION_NOT_IN_POLICY_MESSAGE�len�MisconfiguredEncryptionError�PARTIALLY_CMEK_MESSAGE)r+r,r-�kms_keyr'rr.r/�keys�found_locationr0s           r�
_SetKmsKeyzUpdate._SetKmsKeyys8���-�-�d�.?�.?�.A�B�K�
���#�#�	�!�6�6���;�;�=�	=�"�*�*�!����z�;��W�I�>������.�.�z�:�
��
���%�%�&�*<�*<�*H�*H�*Q�*Q�
�!�;�;���6�6�8�	8��i�
�d��n��'�'�3�3�<�<�'�����8�8��4�4�6�6�����)�)�*��w�'�'�'��.�
�+�+�g�
�
�
.�
.�7�3T�3T�3_�3_�
�+�+�g�7�7�B�B�
C�=��!�:�:���;�;�=�	=�	�Y��3�t�9�	$��5�5��'�'�)�	)�"�*�*�!����z�>�9�d�C������.�.�z�:�
��
�
2�
2��.�.�0�0rc� �tj|j��}|jjj�}|js#|jstjddg��|jr+|jrtj|j��|jr+|jrtj|j��tj|��j|�}|�>tj d|j"j%|j'�����|jr|j)||�S|j+|||j|j�S)Nz
--remove-cmekz
--set-kms-keyrr-)r-)rrr�CONCEPTSr-�Parse�remove_cmek�set_kms_keyr3�MinimumArgumentException�ConflictingArgumentsException�REMOVE_AND_SET_CMEK_MESSAGEr'� REMOVE_CMEK_AND_LOCATION_MESSAGEr!�	GetOrNoner:�SECRET_MISSING_MESSAGE�format�Namer1rB)r+r	rr,r-s     r�Runz
Update.Run�sL���-�-�d�.?�.?�.A�B�K����%�%�+�+�-�J����D�$4�$4��8�8��O�
,�
.�.����D�,�,��=�=�
�
*�
*�
,�,����D�M�M��=�=�
�
/�
/�
1�1��
 �
 �[�
9�
C�
C�J�
O�F�
�~��8�8�
�
�
%�
%�
,�
,�J�O�O�4E�
,�
F�
H�H����
�
�
�j�&�
1�1��?�?�:�v�t�/?�/?����O�OrN)�__name__�
__module__�__qualname__�__doc__�NO_CHANGES_MESSAGErMr7r)r5r;r>rJrK�staticmethodrr1rBrP�rrrrs����DB��>����
<�$�9�!�=�!�L��
P���#�
�3��3�
0�.(0�TPrrN)rT�
__future__rrr�googlecloudsdk.api_lib.secretsrr�googlecloudsdk.callioperrr3�"googlecloudsdk.command_lib.secretsr	rr
r#�
ReleaseTracksr�BETA�GA�
UpdateCommandrrWrr�<module>r`st��!�&��'�=�(�E�C�9�A�����D�%�%�*�*�D�,=�,=�,@�,@�A�aP�T�
�
�aP�B�aPr