googleapis / googleapis/google-cloud-cpp
Implement ADC service account impersonation
- 主要言語
- C++
- スター
- 659
- フォーク
- 462
- 平均マージ
- 1日 2時間
- マージ済み PR(30日)
- 89
説明
This is described internally at [go/adc-impersonation](https://goto.google.com/adc-impersonation)
Basically it requires extending the parsing of the ADC configuration file (if it exists) to support a new type: `impersonated_service_account`. This new type supports the following JSON format:
- `"service_account_impersonation_url"`: `string`, the URL to use for the impersonation workflow.
- Example: `"https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/sa3@developer.gserviceaccount.com:generateAccessToken"`
- `"delegates"`: `array` of `string`. The list of delegates to use in the impersonation workflow.
- Example: `["sa1@developer.gserviceaccount.com", "sa2@developer.gserviceaccount.com" ]`
- `"source_credentials"`: `object` the base credentials to authenticate with.
- `"type"`: `string` the value `"impersonated_service_account"`
Recall that we already implement this form of impersonation for external accounts, so there is existing code to reuse.
For details on the impersonation workflow, see:
https://cloud.google.com/iam/docs/reference/credentials/rest/v1/projects.serviceAccounts/generateAccessToken
コントリビューションガイド
調査の方向性
Start by locating the ADC configuration parser and the existing external-account impersonation implementation referenced in the issue. Read the impersonation workflow requirements and the listed JSON fields, then trace how source credentials, delegates, and the service account impersonation URL are handled. Done means the new impersonated_service_account configuration is parsed and covered by tests.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- cpp, google-cloud
- 領域
- authentication, cloud
- issue の種類
- 機能追加
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 停滞
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 45/100