Swarmauri GCP KMS Key Provider
Google Cloud KMS-backed key provider for the Swarmauri framework. It exposes Cloud KMS asymmetric and symmetric keys through the common IKeyProvider interface so agents can sign, verify, encrypt, decrypt, wrap, and unwrap data without leaving Swarmauri.
Optional Canonicalization Extras
cbor– installscbor2to enable canonical CBOR utilities where workflows require deterministic binary encoding.
Features
- Use Cloud KMS asymmetric keys for RSA/EC signing and verification while receiving RFC 7517 JWKS payloads for downstream services.
- Perform RSA-OAEP wrapping/unwrapping of data encryption keys and AES-256 encryption/decryption with hardware-backed material.
- Publish JWKS documents from Cloud KMS public keys, including caching and TTL-based refresh to minimize API calls.
- Generate random bytes and derive key material via HKDF with SHA-256 for envelope encryption scenarios.
- Destroy individual key versions via the Cloud KMS REST API when performing decommissioning workflows.
Prerequisites
- Python 3.10 or newer.
google-authandrequests(installed automatically) plus network access to Google Cloud KMS endpoints.- A Google Cloud project with the KMS API enabled, along with a key ring (
key_ring_id) in your chosen location (location_id). - Service account or workload identity with permissions such as
cloudkms.cryptoKeys.get,cloudkms.cryptoKeyVersions.useToSign,cloudkms.cryptoKeyVersions.useToDecrypt,cloudkms.cryptoKeys.list, andcloudkms.keyRings.get. - Application Default Credentials available to the runtime (e.g.,
GOOGLE_APPLICATION_CREDENTIALS, workload identity, or Cloud Run default service account).
Installation
# pip
pip install swarmauri_keyprovider_gcpkms
# poetry
poetry add swarmauri_keyprovider_gcpkms
# uv (pyproject-based projects)
uv add swarmauri_keyprovider_gcpkms
# Extras for CBOR canonicalization
pip install "swarmauri_keyprovider_gcpkms[cbor]"
Quickstart: Sign and Verify with Cloud KMS
import asyncio
from swarmauri_keyprovider_gcpkms import GcpKmsKeyProvider
from swarmauri_core.key_providers.types import KeySpec, KeyUse
async def main() -> None:
provider = GcpKmsKeyProvider(
project_id="my-project",
location_id="us-central1",
key_ring_id="swarmauri",
)
key_ref = await provider.get_key(
kid="projects/my-project/locations/us-central1/keyRings/swarmauri/cryptoKeys/jwt-key",
version=None,
)
message = b"payload to sign"
signature = await provider.sign(key_ref.kid, message, alg=JWAAlg.RS256)
await provider.verify(key_ref.kid, message, signature, alg=JWAAlg.RS256)
jwk = await provider.get_public_jwk(key_ref.kid, key_ref.version)
print("Public JWK", jwk)
if __name__ == "__main__":
asyncio.run(main())
Encrypt and Wrap Data Keys
import asyncio
from swarmauri_keyprovider_gcpkms import GcpKmsKeyProvider
async def encrypt_documents() -> None:
provider = GcpKmsKeyProvider(
project_id="my-project",
location_id="us-east1",
key_ring_id="data-protection",
)
dek = await provider.random_bytes(32)
aad = b"swarmauri::tenant-a"
ciphertext = await provider.encrypt(
kid="projects/my-project/locations/us-east1/keyRings/data-protection/cryptoKeys/primary",
plaintext=b"secret payload",
associated_data=aad,
)
wrapped = await provider.wrap(
kid="projects/my-project/locations/us-east1/keyRings/data-protection/cryptoKeys/wrapping",
plaintext=dek,
)
unwrapped = await provider.unwrap(
kid="projects/my-project/locations/us-east1/keyRings/data-protection/cryptoKeys/wrapping",
ciphertext=wrapped,
)
assert unwrapped == dek
# asyncio.run(encrypt_documents())
Operational Tips
- The provider caches public keys (
_pub_cache) for 5 minutes; callget_public_jwk(..., force=True)if you rotate Cloud KMS key versions and need instant propagation. - Use explicit key version names when destroying or disabling keys:
projects/.../cryptoKeys/<name>/cryptoKeyVersions/<n>. - Cloud KMS rotation is controlled outside the provider (per key configuration). Combine the provider with IAM rotation settings to enforce regular key versioning.
- For auditability, inspect the
tagsfield on returnedKeyRefobjects—they include algorithm purpose and key type hints derived from Cloud KMS metadata.
Metadata
Release files for swarmauri_keyprovider_gcpkms 0.9.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_keyprovider_gcpkms-0.9.3.tar.gz | 13.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_keyprovider_gcpkms-0.9.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 26.5 kB
Release files / swarmauri_keyprovider_gcpkms-0.9.3.tar.gz
| Download URL | swarmauri_keyprovider_gcpkms-0.9.3.tar.gz |
|---|---|
| Size | 13.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ed89deb0ad7b6599ee8a87d9ce5c0051f84b9dc46b8d13cfc57d5ad3932c6409
|
|
BLAKE2b-256 checksum How to use checksums |
d02c1d65072bf1bd41e72860d387aff5a43ce0904ce898a45864e907f231055f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_keyprovider_gcpkms-0.9.3-py3-none-any.whl
| Download URL | swarmauri_keyprovider_gcpkms-0.9.3-py3-none-any.whl |
|---|---|
| Size | 12.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d9b772649ea52cc5ad33967a08852d3006c00642dd2e8fb311ed67d8e78883ac
|
|
BLAKE2b-256 checksum How to use checksums |
f6fa959cd787150253163ee6cc73f709bd98b71763201daa69285a9a979a8b76
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|