reqsign_google/lib.rs
1// Licensed to the Apache Software Foundation (ASF) under one
2// or more contributor license agreements. See the NOTICE file
3// distributed with this work for additional information
4// regarding copyright ownership. The ASF licenses this file
5// to you under the Apache License, Version 2.0 (the
6// "License"); you may not use this file except in compliance
7// with the License. You may obtain a copy of the License at
8//
9// http://www.apache.org/licenses/LICENSE-2.0
10//
11// Unless required by applicable law or agreed to in writing,
12// software distributed under the License is distributed on an
13// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14// KIND, either express or implied. See the License for the
15// specific language governing permissions and limitations
16// under the License.
17
18//! Google Service Signer
19//!
20//! Generic service-account impersonation accepts any token-only Google source
21//! provider and can feed its output into a signer or Credential Access Boundary
22//! grant.
23//!
24//! Typed server-side Cloud Storage Credential Access Boundary downscoping is
25//! always available. Enable the `credential-access-boundary-client-side`
26//! feature for local client-side token generation.
27
28mod constants;
29
30mod credential;
31pub use credential::{Credential, ServiceAccount, Token};
32
33mod credential_access_boundary;
34#[cfg(feature = "credential-access-boundary-client-side")]
35pub use credential_access_boundary::ClientSideCredentialAccessBoundaryGranter;
36pub use credential_access_boundary::{
37 CredentialAccessBoundaryGrant, CredentialAccessBoundaryPermissions,
38 ServerSideCredentialAccessBoundaryGranter,
39};
40
41mod service_account_impersonation;
42pub use service_account_impersonation::{
43 ServiceAccountImpersonationCredentialProvider, ServiceAccountImpersonationGrant,
44 ServiceAccountImpersonationGranter,
45};
46
47mod sign_request;
48pub use sign_request::RequestSigner;
49
50mod provide_credential;
51pub use provide_credential::{
52 DefaultCredentialProvider, DefaultCredentialProviderBuilder, EnvCredentialProvider,
53 ExternalAccountConfig, ExternalAccountCredentialProvider, FileCredentialProvider,
54 ServiceAccountTokenCredentialProvider, StaticCredentialProvider, TokenCredentialProvider,
55 VmMetadataCredentialProvider, WellKnownCredentialProvider,
56};