cube-js / cube-js/cube

Can router and workers can support GKE Workload Identity ?

Open
#7,279 1 comment 8 reactions 0 assignees View on GitHub
help wanted
Dominant language
Rust
Stars
20.8k
Forks
2.1k
Avg merge
1d 2h
Merged PRs (30d)
181

Description

**Is your feature request related to a problem? Please describe.**
Without defining "CUBESTORE_GCP_KEY_FILE" in router and worker, I got below error:
thread 'main' panicked at 'SERVICE_ACCOUNT(_JSON) or GOOGLE_APPLICATION_CREDENTIALS(_JSON) environment parameter required: NotPresent'

**Describe the solution you'd like**
Workload Identity allows a Kubernetes service account in your GKE cluster to act as an IAM service account. Pods that use the configured Kubernetes service account automatically authenticate as the IAM service account when accessing Google Cloud APIs.

Referring to https://cube.dev/docs/reference/configuration/environment-variables#cubestore_gcp_key_file
"CUBESTORE_GCP_KEY_FILE" is Required when using Google Cloud Storage and A valid Google Cloud JSON key file is needed.

is there possible to support GKE Workload Identity in future?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.