Expand description
Google Cloud logins through gcloud, and the projects a login can see.
gcloud auth login leaves no file object_store can read: the application-default
file is a separate login that many people never create. So gcloud is asked for a
token, the same way az is, rather than its credential database being read. One
token serves the listing and the open, so a bucket that is listed is one that can
be read.
Each gcloud configuration names an account and a project. Configurations with
different accounts are different logins, and each is a source.
Everything here that runs gcloud or touches the network blocks, and is only called
from a worker.
Structs§
- Configuration
- One
gcloudconfiguration:configurations/config_<name>. - Project
- A project a login can see.
Functions§
- active_
name - The name of the active configuration:
CLOUDSDK_ACTIVE_CONFIG_NAME, else theactive_configfile, elsedefault. - config_
dir - Where
gcloudkeeps its configuration:CLOUDSDK_CONFIG, else%APPDATA%\gcloudon Windows and~/.config/gcloudelsewhere. - configurations
- Every configuration, the active one first, then by name.
- describe_
error 403 PERMISSION_DENIED: ...from a Google error document, with what fixes the common ones.- get
- The body of a Google API’s answer to a GET signed with
bearer, or why it refused. - parse_
config_ helper - The access token and its expiry from
gcloud config config-helper --format=json. A token without a readable expiry is kept for five minutes past the refresh margin. - parse_
configuration - The
[core]account and project of a configuration file. - parse_
projects - One page of
projects:search: active projects, and the next page’s token. - polars_
provider - Polars’ credential provider for a
gcloudconfiguration. One per configuration for the life of the process: Polars caches stores by provider, so a new provider per open would build a new store, and a new connection pool, every time. - search_
projects - Every active project
bearercan see, through Resource Manager’sprojects:search. - token
- A token from
gcloudforconfiguration, with its expiry. Kept until five minutes before it runs out. - unsupported_
credential_ type - The credential type in an application-default credentials file, when it is one
object_store cannot use itself:
external_account(workload identity federation),impersonated_service_account, and anything newer.