Skip to content

cloud: Azure CMEK configuration guide#21770

Merged
ti-chi-bot[bot] merged 19 commits intopingcap:release-8.5from
ginkgoch:feature/cmek-azure
Sep 16, 2025
Merged

cloud: Azure CMEK configuration guide#21770
ti-chi-bot[bot] merged 19 commits intopingcap:release-8.5from
ginkgoch:feature/cmek-azure

Conversation

@ginkgoch
Copy link
Copy Markdown

What is changed, added or deleted? (Required)

  • Add Azure CMEK configuration guide
  • Update existing AWS CMEK for relaxing some of the limitations
  • Add new doc to TOC.

Which TiDB version(s) do your changes apply to? (Required)

Tips for choosing the affected version(s):

By default, CHOOSE MASTER ONLY so your changes will be applied to the next TiDB major or minor releases. If your PR involves a product feature behavior change or a compatibility change, CHOOSE THE AFFECTED RELEASE BRANCH(ES) AND MASTER.

For details, see tips for choosing the affected versions.

  • master (the latest development version)
  • v9.0 (TiDB 9.0 versions)
  • v8.5 (TiDB 8.5 versions)
  • v8.1 (TiDB 8.1 versions)
  • v7.5 (TiDB 7.5 versions)
  • v7.1 (TiDB 7.1 versions)
  • v6.5 (TiDB 6.5 versions)
  • v6.1 (TiDB 6.1 versions)
  • v5.4 (TiDB 5.4 versions)

What is the related PR or file link(s)?

  • This PR is translated from:
  • Other reference link(s):

Do your changes match any of the following descriptions?

  • Delete files
  • Change aliases
  • Need modification after applied to another branch
  • Might cause conflicts after applied to another branch

@ti-chi-bot ti-chi-bot bot added contribution This PR is from a community contributor. first-time-contributor Indicates that the PR was contributed by an external member and is a first-time contributor. labels Sep 12, 2025
@ti-chi-bot
Copy link
Copy Markdown

ti-chi-bot bot commented Sep 12, 2025

Hi @ginkgoch. Thanks for your PR.

I'm waiting for a pingcap member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@ti-chi-bot ti-chi-bot bot added needs-ok-to-test Indicates a PR created by contributors and need ORG member send '/ok-to-test' to start testing. missing-translation-status This PR does not have translation status info. labels Sep 12, 2025
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary of Changes

Hello @ginkgoch, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly expands the documentation for Customer-Managed Encryption Keys (CMEK) in TiDB Cloud by introducing a dedicated guide for Azure. It also refines the existing AWS CMEK documentation, making it more inclusive and removing previous limitations, thereby enhancing the security options available to users for their TiDB Cloud Dedicated clusters.

Highlights

  • New Azure CMEK Configuration Guide: A comprehensive guide has been added detailing how to configure Customer-Managed Encryption Keys (CMEK) for TiDB Cloud Dedicated clusters on Azure, covering steps from project creation to key rotation and access management.
  • Updated AWS CMEK Documentation: The existing AWS CMEK documentation has been updated to reflect broader availability by removing the 'available upon request' restriction and clarifying support for both AWS and Azure CMEK within the same project across multiple regions.
  • Table of Contents Update: The Table of Contents for TiDB Cloud documentation has been updated to include the new Azure CMEK guide and to differentiate the existing CMEK guide specifically for AWS.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point in your pull request via creating an issue comment (i.e. comment on the pull request page) using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in issue comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@ti-chi-bot ti-chi-bot bot added the size/L Denotes a PR that changes 100-499 lines, ignoring generated files. label Sep 12, 2025
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a comprehensive guide for configuring Customer-Managed Encryption Keys (CMEK) on Azure and updates the existing AWS documentation to reflect multi-cloud support. The changes are well-structured and clear. I've added several minor suggestions to the new Azure guide to enhance clarity, correct minor grammatical points, and fix a technical issue with the tabbed content, ensuring a smoother experience for the user.

ginkgoch and others added 11 commits September 12, 2025 14:22
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
@Oreoxmt Oreoxmt self-assigned this Sep 12, 2025
@Oreoxmt Oreoxmt self-requested a review September 12, 2025 07:39
@Oreoxmt Oreoxmt added the translation/no-need No need to translate this PR. label Sep 12, 2025
@Oreoxmt Oreoxmt added area/tidb-cloud This PR relates to the area of TiDB Cloud. for-cloud-release This PR is related to TiDB Cloud release. labels Sep 12, 2025
@ti-chi-bot ti-chi-bot bot removed the missing-translation-status This PR does not have translation status info. label Sep 12, 2025
@ginkgoch ginkgoch requested a review from ideascf September 15, 2025 01:06
@ti-chi-bot
Copy link
Copy Markdown

ti-chi-bot bot commented Sep 15, 2025

@ideascf: adding LGTM is restricted to approvers and reviewers in OWNERS files.

Details

In response to this:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@Oreoxmt Oreoxmt changed the title Azure CMEK configuration guide cloud: Azure CMEK configuration guide Sep 15, 2025
@ti-chi-bot ti-chi-bot bot added the needs-1-more-lgtm Indicates a PR needs 1 more LGTM. label Sep 16, 2025
@hfxsd hfxsd self-requested a review September 16, 2025 06:13
@ti-chi-bot ti-chi-bot bot added lgtm and removed needs-1-more-lgtm Indicates a PR needs 1 more LGTM. labels Sep 16, 2025
@ti-chi-bot
Copy link
Copy Markdown

ti-chi-bot bot commented Sep 16, 2025

[LGTM Timeline notifier]

Timeline:

  • 2025-09-16 06:12:16.966437142 +0000 UTC m=+946603.526318649: ☑️ agreed by Oreoxmt.
  • 2025-09-16 07:49:01.300535418 +0000 UTC m=+952407.860416925: ☑️ agreed by hfxsd.

Co-authored-by: xixirangrang <hfxsd@hotmail.com>
@hfxsd
Copy link
Copy Markdown
Collaborator

hfxsd commented Sep 16, 2025

/retest

@hfxsd
Copy link
Copy Markdown
Collaborator

hfxsd commented Sep 16, 2025

/approve

@ti-chi-bot
Copy link
Copy Markdown

ti-chi-bot bot commented Sep 16, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hfxsd

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ti-chi-bot ti-chi-bot bot added the approved label Sep 16, 2025
@hfxsd
Copy link
Copy Markdown
Collaborator

hfxsd commented Sep 16, 2025

/retest

@hfxsd hfxsd closed this Sep 16, 2025
@hfxsd hfxsd reopened this Sep 16, 2025
@ti-chi-bot ti-chi-bot bot merged commit 3b0ad20 into pingcap:release-8.5 Sep 16, 2025
14 of 22 checks passed
@hfxsd
Copy link
Copy Markdown
Collaborator

hfxsd commented Sep 16, 2025

/approve

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved area/tidb-cloud This PR relates to the area of TiDB Cloud. contribution This PR is from a community contributor. first-time-contributor Indicates that the PR was contributed by an external member and is a first-time contributor. for-cloud-release This PR is related to TiDB Cloud release. lgtm needs-ok-to-test Indicates a PR created by contributors and need ORG member send '/ok-to-test' to start testing. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. translation/no-need No need to translate this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants