[CLDAPP-423] Add Encryption Validation - #113
Open
daehan-temporal wants to merge 3 commits into
Open
daehan-temporal wants to merge 3 commits into
daehan-temporal wants to merge 3 commits into
Conversation
daehan-temporal
marked this pull request as draft
September 15, 2026 07:17
daehan-temporal
requested a deployment
to
integration
September 15, 2026 07:17 — with
GitHub Actions
Waiting
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 8dd25b5. Configure here.
# Conflicts: # go.mod # go.sum # temporalcloudcli/commands.yml
daehan-temporal
force-pushed
the
daehan/eve
branch
from
October 3, 2026 03:06
8dd25b5 to
132c20e
Compare
daehan-temporal
requested a deployment
to
integration
October 3, 2026 03:07 — with
GitHub Actions
Waiting
daehan-temporal
marked this pull request as ready for review
October 5, 2026 19:27
daehan-temporal
requested a deployment
to
integration
October 5, 2026 19:43 — with
GitHub Actions
Waiting
daehan-temporal
requested a deployment
to
integration
October 5, 2026 19:44 — with
GitHub Actions
Waiting
This branch is waiting to be deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What was changed
Adds Cloud CLI support for namespace payload encryption validation (EVE):
namespace createalso accepts optional--encryption-validation-*flags. If any of those flags is set,--encryption-validation-modeis required.warn/encoding/binary/encrypted). Disabled namespaces are re-enabled and keep metadata/inspect. Already-warn or already-deny is left unchanged.--denyonly applies when turning validation on.disabledand keeps metadata/inspect.Bumps
go.temporal.io/cloud-sdktov0.20.0, which includes EncryptionValidation and defaults to Cloud APIv0.23.0.Why?
Give customers a CLI to inspect and change namespace encryption-validation settings, with enable/disable for the common on/off path and set as an explicit replace.
Checklist
Closes - CLDAPP-423
How was this tested:
https://docs.temporal.io/cli/command-reference/cloud/namespace
Note
Medium Risk
Changes namespace security policy (warn/deny can affect workflow acceptance) via full-spec replace on
set; mistakes or omitted flags could misconfigure production namespaces.Overview
Adds Temporal Cloud CLI support for namespace payload encryption validation, bumping
go.temporal.io/cloud-sdkto v0.20.0.New command group
temporal cloud namespace encryption-validationwith get, set, enable, and disable. get prints the currentEncryptionValidationSpec; set fully replaces the nested spec (omitted optional flags become empty/false); enable applies defaults when unconfigured (warn,encoding,binary/encrypted), re-enables fromdisabledwhile keeping metadata/inspect, and leaves existing warn/deny unchanged (optional--deny); disable sets mode todisabledand preserves other fields. Mutations follow the usual get → prompt →UpdateNamespace+ async polling pattern.namespace create gains optional
--encryption-validation-*flags wired throughCreateNamespaceParams; if any encryption-validation flag is set,--encryption-validation-modeis required. Command definitions and tests cover create and the new subcommands; a protoutils golden file picks up the new spec field.Reviewed by Cursor Bugbot for commit eb3778d. Bugbot is set up for automated code reviews on this repo. Configure here.