agents-cli deploy has no way to pass CMEK (encryption_spec) for Agent Runtime, blocking deploys under constraints/gcp.restrictNonCmekServices
- Vorherrschende Sprache
- Python
- Sterne
- 5.9k
- Forks
- 660
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
### What is your feature suggestion?
### Description
Deploying as ADK Agent to Agent Runtime(agents-cli deploy --deployment-target agent_runtime) fails in any GCP project that enforces the org policy constraints/gcp.restrictNonCmekServices, because the CLI never passes a KMS encryption key to the undersying create call.
### Reproduce
agents-cli scaffold create test-a2a-agent --agent adk --deployment-target agent_runtime --region us-central1 --cicd-runner skip
cd test-a2a-agent && agents-cli install
agents-cli deploy --project --region us-central1 --no-confirm-project
### Observed Error
Error: Agent Runtime create request failed — 400 FAILED_PRECONDITION: The request has violated one or more Org Policies: violations {
type: "constraints/gcp.restrictNonCmekServices"
subject: "orgpolicy:projects/"
description: "Constraint `constraints/gcp.restrictNonCmekServices` violated for `projects/` attempting to create a resource without specifying a KMS CryptoKey."
}
### Root cause
- agents-cli deploy --help exposes flags for --network-attachment, --service-account, --agent-gateway-*, etc., but has no --kms-key / --encryption-spec flag.
- The underlying SDK (vertexai.agent_engines._agent_engines.create(), in google_cloud_aiplatform==1.165.1 as vendored by the CLI) already accepts an encryption_spec: Optional[aip_types.EncryptionSpec] parameter — the capability exists in the SDK layer, it's just never threaded through google/agents/cli/deploy/cmd_deploy.py / agent_runtime.py.
### Requested fix
Add a --kms-key (or --encryption-spec) flag to agents-cli deploy for the agent_runtime target
### What will this enable you to do?
Any organization that mandates CMEK for Vertex AI resources (a common enterprise/regulated-industry policy) cannot deploy to Agent Runtime via agents-cli at all — there is no workaround short of bypassing the CLI and calling the
### Additional context
_No response_
Beitragsleitfaden
Rechercherichtung
Beginne mit google/agents/cli/deploy/cmd_deploy.py und agent_runtime.py und untersuche anschließend vertexai.agent_engines._agent_engines.create() auf seinen Parameter encryption_spec. Führe den Reproduktionsbefehl gegen ein Projekt aus, das constraints/gcp.restrictNonCmekServices erzwingt, und untersuche agents-cli deploy --help. Erledigt bedeutet, dass ein agent_runtime deploy den KMS-Verschlüsselungsschlüssel empfangen und diese Richtlinie erfüllen kann.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- google-cloud, python
- Bereich
- cli, cloud
- Issue-Typ
- Feature
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Aktivitätsstatus
- Aktiv
- Klarheit
- Klar beschrieben
- Anfängerfreundlichkeit
- 72/100