Expired authentication credentials are reported as HTTP 503 (Service Unavailable) errors

Aperta
#18,419 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
65/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
google-cloud, python

Direzione di ricerca

Reproduce the failure from stormware/google/secrets.py at line 71 using expired credentials, then trace the generated Secret Manager client through google/api_core/gapic_v1/method.py and google/api_core/retry/retry_unary.py. Done means expired-credential failures surface immediately as an authentication error rather than being retried as HTTP 503 until the 60-second timeout.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

triage me type: bug
Determine this is the right repository
  • I determined this is the correct repository in which to report this bug.
Summary of the issue

Context
Whenever we try to use the SDK clients with expired authentication credentials our programs halt for 60 seconds. This is because such requests get a 503 HTTP response back (which is not the correct response), so the library keeps retrying until the default timeout (which is 60 seconds).

Expected Behavior:
We expect SDK clients to fail immediately when credentials are expired.

Actual Behavior:
SDK clients do not fail immediately when credentials are expired.

API client name and version

google-cloud-secret-manager==2.30.0

Reproduction steps: code

See https://github.com/logikal-io/stormware/blob/main/stormware/google/secrets.py#L71.

Reproduction steps: supporting files

No response

Reproduction steps: actual results

The errors seen are as follows:

  File ".../lib/python3.12/site-packages/stormware/google/secrets.py", line 71, in __getitem__
    response = self.client.access_secret_version(name=name)
               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File ".../lib/python3.12/site-packages/google/cloud/secretmanager_v1/services/secret_manager_service/client.py", line 1875, in access_secret_version
    response = rpc(
               ^^^^
  File ".../lib/python3.12/site-packages/google/api_core/gapic_v1/method.py", line 373, in __call__
    result = wrapped_func(*args, **kwargs)
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File ".../lib/python3.12/site-packages/google/api_core/retry/retry_unary.py", line 295, in retry_wrapped_func
    return retry_target(
           ^^^^^^^^^^^^^
  File ".../lib/python3.12/site-packages/google/api_core/retry/retry_unary.py", line 157, in retry_target
    next_sleep = _retry_error_helper(
                 ^^^^^^^^^^^^^^^^^^^^
  File ".../lib/python3.12/site-packages/google/api_core/retry/retry_base.py", line 230, in _retry_error_helper
    raise final_exc from source_exc
google.api_core.exceptions.RetryError: Timeout of 60.0s exceeded, last exception: 503 Getting metadata from plugin failed with error: Reauthentication is needed. Please run `gcloud auth application-default login` to reauthenticate.
Reproduction steps: expected results

We'd expect these calls to fail immediately.

OS & version + platform

No response

Python environment

No response

Python dependencies

No response

Additional context

No response

Lingua principale
Python
Stelle
5.4k
Fork
1.8k
Merge medio
2g 22h
PR unite (30g)
102

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di googleapis/google-cloud-python

Tutte le issue di googleapis/google-cloud-python

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.