googleapis / googleapis/google-cloud-cpp

Implement ADC service account impersonation

Open
#12,497 3 comments 0 reactions 0 assignees View on GitHub
type: feature request
Dominant language
C++
Stars
659
Forks
462
Avg merge
1d 2h
Merged PRs (30d)
89

Description

This is described internally at [go/adc-impersonation](https://goto.google.com/adc-impersonation)

Basically it requires extending the parsing of the ADC configuration file (if it exists) to support a new type: `impersonated_service_account`. This new type supports the following JSON format:

- `"service_account_impersonation_url"`: `string`, the URL to use for the impersonation workflow.
- Example: `"https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/sa3@developer.gserviceaccount.com:generateAccessToken"`
- `"delegates"`: `array` of `string`. The list of delegates to use in the impersonation workflow.
- Example: `["sa1@developer.gserviceaccount.com", "sa2@developer.gserviceaccount.com" ]`
- `"source_credentials"`: `object` the base credentials to authenticate with.
- `"type"`: `string` the value `"impersonated_service_account"`

Recall that we already implement this form of impersonation for external accounts, so there is existing code to reuse.

For details on the impersonation workflow, see:

https://cloud.google.com/iam/docs/reference/credentials/rest/v1/projects.serviceAccounts/generateAccessToken

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.