googleapis / googleapis/google-cloud-cpp

Investigate automatic detection of CA roots from environment variables (e.g. CURL_CA_BUNDLE)

Open
#15,822 0 comments 0 reactions 0 assignees View on GitHub
priority: p3 type: bug
Dominant language
C++
Stars
659
Forks
462
Avg merge
1d 2h
Merged PRs (30d)
89

Description

**Problem**
Currently, to make the `quickstart` examples work in the Windows Bazel CI environment (which uses a hermetic build with custom OpenSSL roots), we explicitly modify the C++ code to read the `CURL_CA_BUNDLE` environment variable and set the `CARootsFilePathOption`.

See PR #15818 for the current implementation

**Goal**
We should explore ways to avoid modifying the example code (`quickstart.cc`) for this CI-specific configuration.

**Potential Solutions**
- Update the client library to automatically check `CURL_CA_BUNDLE` or standard OpenSSL environment variables when initializing the default `Options`.
- Adjust the Bazel build configuration to transparently point to the correct roots without code changes.

This issue tracks the investigation and implementation of a solution that keeps the quickstart code clean and environment-agnostic.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.