Skip to main content

Module gcloud

Module gcloud 

Source
Expand description

Google Cloud logins through gcloud, and the projects a login can see.

gcloud auth login leaves no file object_store can read: the application-default file is a separate login that many people never create. So gcloud is asked for a token, the same way az is, rather than its credential database being read. One token serves the listing and the open, so a bucket that is listed is one that can be read.

Each gcloud configuration names an account and a project. Configurations with different accounts are different logins, and each is a source.

Everything here that runs gcloud or touches the network blocks, and is only called from a worker.

Structs§

Configuration
One gcloud configuration: configurations/config_<name>.
Project
A project a login can see.

Functions§

active_name
The name of the active configuration: CLOUDSDK_ACTIVE_CONFIG_NAME, else the active_config file, else default.
config_dir
Where gcloud keeps its configuration: CLOUDSDK_CONFIG, else %APPDATA%\gcloud on Windows and ~/.config/gcloud elsewhere.
configurations
Every configuration, the active one first, then by name.
describe_error
403 PERMISSION_DENIED: ... from a Google error document, with what fixes the common ones.
get
The body of a Google API’s answer to a GET signed with bearer, or why it refused.
parse_config_helper
The access token and its expiry from gcloud config config-helper --format=json. A token without a readable expiry is kept for five minutes past the refresh margin.
parse_configuration
The [core] account and project of a configuration file.
parse_projects
One page of projects:search: active projects, and the next page’s token.
polars_provider
Polars’ credential provider for a gcloud configuration. One per configuration for the life of the process: Polars caches stores by provider, so a new provider per open would build a new store, and a new connection pool, every time.
search_projects
Every active project bearer can see, through Resource Manager’s projects:search.
token
A token from gcloud for configuration, with its expiry. Kept until five minutes before it runs out.
unsupported_credential_type
The credential type in an application-default credentials file, when it is one object_store cannot use itself: external_account (workload identity federation), impersonated_service_account, and anything newer.