GoogleCloudPlatform / GoogleCloudPlatform/cloud-sql-python-connector

Make user optional when passing enable_iam_auth

Offen
#310 2 Kommentare 2 Reaktionen 1 zugewiesene Person Zugewiesen an @hessjcg Auf GitHub ansehen
priority: p2 type: feature request
Vorherrschende Sprache
Python
Sterne
344
Forks
89
Ø Merge
5 Std. 33 Min.
Gemergte PRs (30 T.)
2

Beschreibung

## Feature Description

If I'm using this in an environment like cloud run, there really only is one account - the currently active service account. I think the default assumption is that the user that is going to be doing the proxying is also the one that is being logged in, so it's quite redundant to have to get the current service account, and then chop off the `gserviceaccount.com` as required.

A cleaner API would be to simply no longer have user required when enable_iam_auth is passed, and have the connector correctly detect service account emails and appropriately chop them, cleanly abstracting away the internals.

That would take the common use case from
```
account = detect_account()
if account.endswith(".iam.gserviceaccount.com"):
account = account.replace(".gserviceaccount.com", "")
connector.connect(MY_DB_STR, "pg8000", user=account, db=MY_DB, enable_iam_auth=True)
```
to the extremely elegant `connector.connect(MY_DB_STR, "pg8000", db=MY_DB, enable_iam_auth=True)`

## Alternatives Considered
We could continue to keep this redundant, but it's forcing the calling code to still be dealing with GCP internals.

Thank you for your consideration :P

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.