Validate Project of staging bucket#39008
Conversation
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request introduces a parity feature with the Java SDK by enforcing project ownership validation for default GCS staging buckets. By utilizing the Cloud Resource Manager API, the pipeline now verifies that the staging bucket belongs to the executing project, preventing potential cross-project access issues. Highlights
New Features🧠 You can now enable Memory (public preview) to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request introduces ownership validation for pre-existing default GCS buckets to ensure they are owned by the executing project, utilizing the Cloud Resource Manager API. It also adds corresponding unit tests and the google-cloud-resource-manager dependency. The reviewer feedback suggests making the validation more robust by handling missing project numbers and API exceptions gracefully, optimizing the project number resolution when the ID is already numeric, and safely accessing the private _credentials attribute using getattr.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
|
Stopping reviewer notifications for this pull request: review requested by someone other than the bot, ceding control. If you'd like to restart, comment |
|
Failing Tests are not relevant. This is done from my end. Thanks! |
Parity feature, similar to Java. Validate that bucket is in the same project as the pipeline when Beam defaults the default naming conventions.
Introducing google-cloud-resource-manager for mapping project_name to project_number. Java used the same dependency for this
beam/sdks/java/extensions/google-cloud-platform-core/src/main/java/org/apache/beam/sdk/extensions/gcp/options/GcpOptions.java
Line 527 in 849fcf8
Existing Java:


Python:
GitHub Actions Tests Status (on master branch)
See CI.md for more information about GitHub Actions CI or the workflows README to see a list of phrases to trigger workflows.