googleapis / googleapis/google-cloud-cpp

Implement ADC service account impersonation

Offen
#12,497 3 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
type: feature request
Vorherrschende Sprache
C++
Sterne
659
Forks
462
Ø Merge
1 T. 2 Std.
Gemergte PRs (30 T.)
89

Beschreibung

This is described internally at [go/adc-impersonation](https://goto.google.com/adc-impersonation)

Basically it requires extending the parsing of the ADC configuration file (if it exists) to support a new type: `impersonated_service_account`. This new type supports the following JSON format:

- `"service_account_impersonation_url"`: `string`, the URL to use for the impersonation workflow.
- Example: `"https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/sa3@developer.gserviceaccount.com:generateAccessToken"`
- `"delegates"`: `array` of `string`. The list of delegates to use in the impersonation workflow.
- Example: `["sa1@developer.gserviceaccount.com", "sa2@developer.gserviceaccount.com" ]`
- `"source_credentials"`: `object` the base credentials to authenticate with.
- `"type"`: `string` the value `"impersonated_service_account"`

Recall that we already implement this form of impersonation for external accounts, so there is existing code to reuse.

For details on the impersonation workflow, see:

https://cloud.google.com/iam/docs/reference/credentials/rest/v1/projects.serviceAccounts/generateAccessToken

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by locating the ADC configuration parser and the existing external-account impersonation implementation referenced in the issue. Read the impersonation workflow requirements and the listed JSON fields, then trace how source credentials, delegates, and the service account impersonation URL are handled. Done means the new impersonated_service_account configuration is parsed and covered by tests.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
cpp, google-cloud
Bereich
authentication, cloud
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
45/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.