-
Notifications
You must be signed in to change notification settings - Fork 8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add cache over gcp_get_secret_value #616
Conversation
WalkthroughThe change introduces a new function, Changes
Sequence Diagram(s)sequenceDiagram
participant Caller as Function Caller
participant Cache as Cache Decorator
participant GID as get_gcloud_project_id()
participant SMClient as SecretManagerServiceClient
Caller ->> Cache: Call gcp_get_secret_value(name, version)
alt Cache Miss
Cache ->> GID: Retrieve project ID
GID -->> Cache: Return project_id
Cache ->> SMClient: Access secret version for constructed resource name
SMClient -->> Cache: Return secret data
Cache -->> Caller: Return secret value (and cache it)
else Cache Hit
Cache -->> Caller: Return cached secret value
end
✨ Finishing Touches
Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media? 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 0
🔭 Outside diff range comments (1)
prediction_market_agent_tooling/deploy/gcp/utils.py (1)
202-206
: 🛠️ Refactor suggestionAdd error handling and improve type hints.
The function should handle potential errors when accessing secrets and provide complete type hints.
Consider this implementation:
-def gcp_get_secret_value(name: str, version: str = "latest") -> str: - client = SecretManagerServiceClient() - return client.access_secret_version( - name=f"projects/{get_gcloud_project_id()}/secrets/{name}/versions/{version}" - ).payload.data.decode("utf-8") +from google.api_core import exceptions +from google.cloud.secretmanager_v1.types import AccessSecretVersionResponse + +def gcp_get_secret_value(name: str, version: str = "latest") -> str: + """Retrieve a secret value from Google Cloud Secret Manager. + + Args: + name: The name of the secret. + version: The version of the secret (default: "latest"). + + Returns: + The secret value as a string. + + Raises: + ValueError: If the secret or version doesn't exist. + RuntimeError: If there's an error accessing the secret. + """ + client = SecretManagerServiceClient() + try: + response: AccessSecretVersionResponse = client.access_secret_version( + name=f"projects/{get_gcloud_project_id()}/secrets/{name}/versions/{version}" + ) + return response.payload.data.decode("utf-8") + except exceptions.NotFound: + raise ValueError(f"Secret {name} (version: {version}) not found") + except Exception as e: + raise RuntimeError(f"Error accessing secret {name}: {e}") from e
🧹 Nitpick comments (1)
prediction_market_agent_tooling/deploy/gcp/utils.py (1)
201-206
: Consider security implications of caching secrets.While caching secret values improves performance by reducing API calls, it has important implications:
- Secrets remain in memory indefinitely
- No cache invalidation mechanism for rotated secrets
- Potential memory leak if many different secret names/versions are accessed
Consider these alternatives:
- Use
@lru_cache
withmaxsize
to limit memory usage- Implement a time-based cache invalidation
- Add explicit cache clearing method
Example implementation with
lru_cache
:-@cache +from functools import lru_cache + +@lru_cache(maxsize=100) def gcp_get_secret_value(name: str, version: str = "latest") -> str:
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
⛔ Files ignored due to path filters (1)
pyproject.toml
is excluded by!**/*.toml
📒 Files selected for processing (1)
prediction_market_agent_tooling/deploy/gcp/utils.py
(2 hunks)
⏰ Context from checks skipped due to timeout of 90000ms (6)
- GitHub Check: pytest - Python 3.12.x - Integration with Local Chain
- GitHub Check: pytest - Python 3.12.x - Unit Tests
- GitHub Check: pytest - Python 3.11.x - Integration with Local Chain
- GitHub Check: pytest - Python 3.11.x - Unit Tests
- GitHub Check: pytest - Python 3.10.x - Integration with Local Chain
- GitHub Check: pytest - Python 3.10.x - Unit Tests
🔇 Additional comments (1)
prediction_market_agent_tooling/deploy/gcp/utils.py (1)
4-4
: LGTM!The import of
cache
decorator is correctly placed with other standard library imports.
No description provided.