Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To reload a Google Cloud Secret Manager value in a running Go service, the app must do more than create a new secret version: it must resolve the version again, validate the resulting configuration, and apply it to the running process. With mamori, you can bind a gcp-sm:// reference to a config field and refresh it through the provider’s polling watch or an on-demand load triggered by your own Pub/Sub subscriber.

What changes when a Secret Manager version changes?

Secret Manager stores secret data as versions. A Go application reads a version by calling Secret Manager; storing a new version does not, by itself, replace a value already loaded into the process. Google’s Go access example uses cloud.google.com/go/secretmanager/apiv1 and calls AccessSecretVersion. The resource name can identify a numeric version or an alias such as latest (Google Cloud: Access a secret version).

Likewise, a change notification is not a secret value and does not reload your configuration automatically. Google publishes Pub/Sub messages about resource changes; calls to Get, List, and Access do not themselves publish change notifications (Google Cloud: Set up notifications on a secret). Your application needs a refresh path that reads the desired version and then safely updates its in-memory state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose whether the reference follows latest or pins a version

mamori documents references in this form: gcp-sm://<project>/<secret>[#json-key][?version=<v>]. If you omit the version, its provider documentation says the lookup defaults to latest; setting ?version=N pins the reference to a specific version (mamori GCP provider documentation).

Choice Operational effect Useful when
Omit version and follow latest A fresh lookup can resolve the moving alias to the current version, so the application must refresh and decide when to adopt it. A changing credential should be picked up through a controlled refresh flow.
Set ?version=N The reference stays tied to that version until you change the configuration. You want reproducible deployments, deliberate promotion, or a controlled rollback.

Google’s production guidance advises specifying a version ID rather than using latest (Google Cloud: Create and access a secret). That guidance favors explicit control; following latest instead makes sense when the service is intentionally designed to track rotations. Neither choice removes the need to refresh the value inside the process.

Configure mamori to resolve the secret

Grant the service access and configure credentials

The mamori provider documentation says it authenticates with Application Default Credentials (ADC). Configure ADC in the environment where the Go service runs, and grant that identity access only to the secrets the service needs. Check Google Cloud’s current IAM documentation for the exact permissions and role appropriate to your deployment rather than granting broad project access by default.

Install and register the provider

mamori’s documented installation command is:

go get github.com/xavidop/mamori/providers/gcp

Register the provider with a blank import, following the documented package path:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import _ "github.com/xavidop/mamori/providers/gcp"

These installation and registration steps reflect mamori’s provider documentation; confirm the package’s current setup guidance when integrating it.

Bind a reference to a typed configuration field

Use the documented URI grammar as the value for the relevant mamori configuration field. For example, a reference that follows the current version can be written as:

gcp-sm://my-project/api-credential

To pin a lookup to a chosen version, include its version number:

gcp-sm://my-project/service-config?version=7

The documented grammar also permits a JSON key fragment, such as #username, when the secret payload is JSON and the configuration needs one key. Bind the reference to the appropriate typed field, load the initial configuration, and validate it before the service begins using it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Refresh the running configuration

mamori documents its GCP watch behavior as polling, with an interval and jitter. Polling is the provider’s mechanism for noticing changes; it is not an instant push from Secret Manager. The documentation also describes Pub/Sub as a way to trigger an on-demand load when the application wires that path (mamori GCP provider documentation).

  1. Load an initial snapshot. Resolve the configuration reference at startup and validate the resulting values before making them active.
  2. Choose a refresh trigger. Use the provider’s documented polling watch, or subscribe to an appropriate Pub/Sub notification and call the application’s load path when a relevant event arrives.
  3. Resolve and validate again. A trigger only tells the service to check; the app still needs to load the secret version and reject invalid or incomplete configuration.
  4. Apply the new value deliberately. Update the live component that consumes the credential or configuration, and handle failures without discarding a working value prematurely.

Google’s event notifications describe changes to secret resources, not a direct delivery of the secret into your process. In particular, the Access call itself does not generate a change event, so a service cannot rely on its own reads to notify it that a later version exists (Google Cloud: Set up notifications on a secret).

Understand what scheduled rotation does—and does not do

A Secret Manager rotation schedule sends a SECRET_ROTATE message to configured Pub/Sub topics at the scheduled time. The message is part of a workflow: a subscriber must act on it, and that work may include creating a new secret version and deploying or coordinating changes in dependent systems. The schedule does not, by itself, change the downstream credential or update application state (Google Cloud: Create rotation schedules in Secret Manager).

For a Go service, treat the notification as a reason to initiate the appropriate rotation workflow, not as proof that a replacement value is ready to use. Refreshing an alias such as latest can retrieve a newly created version, but your service still needs to validate and adopt it at a safe point.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Pick a refresh policy that matches the value

Use polling when periodic checks are acceptable

Polling keeps the refresh mechanism within mamori’s documented watch path. Its operational trade-off is that detection happens on the polling schedule rather than immediately at the moment a version is created. The provider documentation mentions an interval and jitter but does not establish a measured refresh delay, so set expectations from your actual configuration and service requirements.

Use Pub/Sub when you need an event-triggered check

A subscriber can use a relevant Secret Manager event to request an on-demand load. This can avoid waiting for the next poll, but it adds a subscriber path that your service must configure and operate. The event prompts a read; it does not contain the replacement secret value or apply it to the application automatically.

Adopt credentials atomically

Separate fetching from activation. Load into a candidate configuration, validate it, and only then replace the active value or reinitialize the dependent client. If loading or validation fails, keep the currently working configuration and surface the failure through your normal operational monitoring. This avoids turning a refresh attempt into an unplanned outage.

Common reasons a reload does not take effect

  • A new version exists, but the service still uses its startup snapshot. Add a refresh path; Secret Manager does not push values into the process.
  • The reference is pinned. A ?version=N reference continues to request that version; change the configured version deliberately if you want to promote another one.
  • The app receives a Pub/Sub message but never loads again. Wire the subscriber to an on-demand load, then validate and apply the result.
  • The app follows latest but never checks it again. The alias can only affect a new lookup; configure polling or another refresh trigger.
  • The identity cannot access the secret. Verify ADC in the service’s runtime environment and its narrowly scoped Secret Manager access.
  • The new value is invalid or not yet usable. Validate before activation and preserve the existing working configuration if the candidate fails.

Sources and version-sensitive setup

Google’s documentation covers Go access, version aliases, Pub/Sub change notifications, rotation schedules, and its production guidance on version IDs. mamori’s provider page documents the URI format, ADC, polling, and version selection. Its general quick start currently states a Go 1.26-or-newer requirement; because Go and package requirements can change, check the current quick start before adopting that prerequisite (mamori quick start).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.