GoogleCloudPlatform / GoogleCloudPlatform/artifact-registry-python-tools

Support for skipping ADC/using only `gcloud` auth?

Open
#22 3 comments 4 reactions 1 assignee Claimed by @megan-kuo View on GitHub
Dominant language
Python
Stars
23
Forks
11
PR merge metrics
No merged PRs in 30d

Description

As a developer, when using the plugin in conjunction with `twine` for uploading packages to a registry, I don't typically want to have the `GOOGLE_APPLICATION_CREDENTIALS` set to a local key, since I'm using `gcloud auth login` for most other things. And, developing on a local workstation, I don't have a reachable metadata service either.

In that usage, a typical session looks something like:

```
-> % twine upload --non-interactive --repository-url https://europe-west2-python.pkg.dev/MYPROJECT/py-test-repo/ dist/somepackage-2.0.0* --verbose -c 'hello'
Uploading distributions to https://europe-west2-python.pkg.dev/MYPROJECT/py-test-repo/
dist/somepackage-2.0.0-py3-none-any.whl (261.8 KB)
WARNING:root:Failed to retrieve Application Default Credentials: Could not automatically determine credentials. Please set GOOGLE_APPLICATION_CREDENTIALS or explicitly create credentials and re-run the application. For more information, please see https://cloud.google.com/docs/authentication/getting-started
WARNING:root:Trying to retrieve credentials from gcloud...
username set from keyring
INFO:twine.auth:username set from keyring
WARNING:google.auth.compute_engine._metadata:Compute Engine Metadata server unavailable on attempt 1 of 3. Reason: timed out
WARNING:google.auth.compute_engine._metadata:Compute Engine Metadata server unavailable on attempt 2 of 3. Reason: [Errno 113] No route to host
WARNING:google.auth.compute_engine._metadata:Compute Engine Metadata server unavailable on attempt 3 of 3. Reason: timed out
WARNING:google.auth._default:Authentication failed using Compute Engine authentication due to unavailable metadata server.
WARNING:root:Failed to retrieve Application Default Credentials: Could not automatically determine credentials. Please set GOOGLE_APPLICATION_CREDENTIALS or explicitly create credentials and re-run the application. For more information, please see https://cloud.google.com/docs/authentication/getting-started
WARNING:root:Trying to retrieve credentials from gcloud...
password set from keyring
INFO:twine.auth:password set from keyring
username: oauth2accesstoken
INFO:twine.repository:username: oauth2accesstoken
password:
INFO:twine.repository:password:
Uploading somepackage-2.0.0-py3-none-any.whl
```

Where the ADC error spam and delays checking for a metadata service somewhat hinder the usability of this approach.

If I explicitly set GOOGLE_APPLICATION_CREDENTIALS to something invalid, it appears to skip the metadata check, but still not ideal:

```
> % GOOGLE_APPLICATION_CREDENTIALS=/dev/null twine upload --non-interactive --repository-url https://europe-west2-python.pkg.dev/MYPROJECT/py-test-repo/ dist/somepackage-2.0.0* --verbose -c 'hello'
Uploading distributions to https://europe-west2-python.pkg.dev/MYPROJECT/py-test-repo/
dist/somepackage-2.0.0-py3-none-any.whl (261.8 KB)
dist/somepackage-2.0.0.linux-x86_64.tar.gz (148.6 KB)
dist/somepackage-2.0.0.tar.gz (256.0 KB)
WARNING:root:Failed to retrieve Application Default Credentials: ('File /dev/null is not a valid json file.', JSONDecodeError('Expecting value: line 1 column 1 (char 0)'))
WARNING:root:Trying to retrieve credentials from gcloud...
username set from keyring
INFO:twine.auth:username set from keyring
WARNING:root:Failed to retrieve Application Default Credentials: ('File /dev/null is not a valid json file.', JSONDecodeError('Expecting value: line 1 column 1 (char 0)'))
WARNING:root:Trying to retrieve credentials from gcloud...
password set from keyring
INFO:twine.auth:password set from keyring
username: oauth2accesstoken
INFO:twine.repository:username: oauth2accesstoken
password:
INFO:twine.repository:password:
Uploading somepackage-2.0.0-py3-none-any.whl
```

I'm not sure what the best solution that doesn't compromise usability or debugging for the probably-more-common automation/CI uses, but one idea would be checking for an explicit `GOOGLE_APPLICATION_CREDENTIALS` value and skipping the ADC attempt if it matches (or running it but suppressing output?) I was thinking maybe `/dev/null` as a flag value, since it shouldn't cause any harm to any other processes if they also happen to read it and attempt ADC.

A separate env var (`KEYRING_ARTIFACTREG_AUTH_GCLOUD_FIRST` or something?) could also maybe work.

One final option might be checking if the supplied username is some specific value, but that relies on all the keyring-consuming apps to correctly allow for the keyring interface modifying the provided username to `get_credential()`, which apparently at least Twine doesn't do properly.

See fork/commit referenced below (https://github.com/camresp/artifact-registry-python-tools/tree/poc-skip-adc) for a hacky version of the various options, the 2 env-var variants work, but the username doesn't, at least with `twine`.

Happy to make a better PR if there's interest in one or more of the approaches.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.