googleapis / googleapis/google-cloud-node

Connect to IAP protected endpoint with Workload Identity Federation

Open
#7,744 6 comments 4 reactions 0 assignees View on GitHub
library: google-cloud-node-core priority: p3 type: feature request
Dominant language
TypeScript
Stars
3.2k
Forks
712
Avg merge
2d 3h
Merged PRs (30d)
99

Description

Hi!
I'm trying to create setup where I can run my code that will impersonate SA based on Workload Identity Federation and then call IAP protected endpoint (running on Cloud Run).
I've managed to do such setup with Python library but I'm unable to do it in nodejs.

I've tried to combine samples regarding WIF and IAP but without any luck.

When running `const client = await auth.getIdTokenClient(targetAudience);` I'm getting error: `Cannot fetch ID token in this environment, use GCE or set the GOOGLE_APPLICATION_CREDENTIALS environment variable to a service account credentials JSON file.`
My `GOOGLE_APPLICATION_CREDENTIALS` var is pointing to valid `external_account` credentials file.

Could you please point me to right solution?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.