Skip to content

GCS: Support Node/VM identity auth. - #33

Merged
achudnovskij merged 1 commit into
mainfrom
gcs-metadata-auth
Sep 27, 2026
Merged

achudnovskij merged 1 commit into
mainfrom
gcs-metadata-auth

Conversation

@achudnovskij

@achudnovskij achudnovskij commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Support Node/VM identity auth to GCS via metadata server.
Similarly to AWS activated when GOOGLE_APPLICATION_CREDENTIALS not provided.

Without GOOGLE_APPLICATION_CREDENTIALS, mint the bearer token from the
GCE/GKE metadata server (the VM's attached service account) instead of
failing with "metadata-server auth not yet supported". This mirrors the
S3 "no static keys -> EC2 IMDS" default, i.e. node identity.

The key-file path is unchanged. Both sources share the token cache and
response handling. The metadata client bypasses proxies and uses short
timeouts, as the IMDS client does. GcsConfig is untouched, so there is
no public API change; GCE_METADATA_HOST is not read.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@achudnovskij
achudnovskij marked this pull request as ready for review September 27, 2026 13:54
@achudnovskij achudnovskij changed the title GCS: metadata-server (node identity) auth fallback GCS: Support Node/VM identity auth. Sep 27, 2026
@achudnovskij
achudnovskij merged commit e844dff into main Sep 27, 2026
93 checks passed
@achudnovskij
achudnovskij deleted the gcs-metadata-auth branch September 27, 2026 14:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants