googleapis / googleapis/google-cloud-cpp

Implement ADC service account impersonation

オープン
#12,497 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る
type: feature request
主要言語
C++
スター
659
フォーク
462
平均マージ
1日 2時間
マージ済み PR(30日)
89

説明

This is described internally at [go/adc-impersonation](https://goto.google.com/adc-impersonation)

Basically it requires extending the parsing of the ADC configuration file (if it exists) to support a new type: `impersonated_service_account`. This new type supports the following JSON format:

- `"service_account_impersonation_url"`: `string`, the URL to use for the impersonation workflow.
- Example: `"https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/sa3@developer.gserviceaccount.com:generateAccessToken"`
- `"delegates"`: `array` of `string`. The list of delegates to use in the impersonation workflow.
- Example: `["sa1@developer.gserviceaccount.com", "sa2@developer.gserviceaccount.com" ]`
- `"source_credentials"`: `object` the base credentials to authenticate with.
- `"type"`: `string` the value `"impersonated_service_account"`

Recall that we already implement this form of impersonation for external accounts, so there is existing code to reuse.

For details on the impersonation workflow, see:

https://cloud.google.com/iam/docs/reference/credentials/rest/v1/projects.serviceAccounts/generateAccessToken

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start by locating the ADC configuration parser and the existing external-account impersonation implementation referenced in the issue. Read the impersonation workflow requirements and the listed JSON fields, then trace how source credentials, delegates, and the service account impersonation URL are handled. Done means the new impersonated_service_account configuration is parsed and covered by tests.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
cpp, google-cloud
領域
authentication, cloud
issue の種類
機能追加
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。