googleapis / googleapis/google-cloud-cpp
Investigate automatic detection of CA roots from environment variables (e.g. CURL_CA_BUNDLE)
- Dominant language
- C++
- Stars
- 659
- Forks
- 462
- Avg merge
- 1d 2h
- Merged PRs (30d)
- 89
Description
**Problem**
Currently, to make the `quickstart` examples work in the Windows Bazel CI environment (which uses a hermetic build with custom OpenSSL roots), we explicitly modify the C++ code to read the `CURL_CA_BUNDLE` environment variable and set the `CARootsFilePathOption`.
See PR #15818 for the current implementation
**Goal**
We should explore ways to avoid modifying the example code (`quickstart.cc`) for this CI-specific configuration.
**Potential Solutions**
- Update the client library to automatically check `CURL_CA_BUNDLE` or standard OpenSSL environment variables when initializing the default `Options`.
- Adjust the Bazel build configuration to transparently point to the correct roots without code changes.
This issue tracks the investigation and implementation of a solution that keeps the quickstart code clean and environment-agnostic.
Contributor guide
Assessment
This issue has not been assessed yet.