Skip to content

Commit bdefdc3

Browse files
authored
use google default application credentials (#5)
instead of hitting the metadata server
1 parent ec190c0 commit bdefdc3

4 files changed

Lines changed: 133 additions & 94 deletions

File tree

.gitignore

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
lightsout

go.mod

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,33 @@
11
module github.com/libops/lightsout
22

33
go 1.25.3
4+
5+
require (
6+
golang.org/x/oauth2 v0.33.0
7+
google.golang.org/api v0.256.0
8+
)
9+
10+
require (
11+
cloud.google.com/go/auth v0.17.0 // indirect
12+
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
13+
cloud.google.com/go/compute/metadata v0.9.0 // indirect
14+
github.com/felixge/httpsnoop v1.0.4 // indirect
15+
github.com/go-logr/logr v1.4.3 // indirect
16+
github.com/go-logr/stdr v1.2.2 // indirect
17+
github.com/google/s2a-go v0.1.9 // indirect
18+
github.com/google/uuid v1.6.0 // indirect
19+
github.com/googleapis/enterprise-certificate-proxy v0.3.7 // indirect
20+
github.com/googleapis/gax-go/v2 v2.15.0 // indirect
21+
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
22+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 // indirect
23+
go.opentelemetry.io/otel v1.38.0 // indirect
24+
go.opentelemetry.io/otel/metric v1.38.0 // indirect
25+
go.opentelemetry.io/otel/trace v1.38.0 // indirect
26+
golang.org/x/crypto v0.45.0 // indirect
27+
golang.org/x/net v0.47.0 // indirect
28+
golang.org/x/sys v0.38.0 // indirect
29+
golang.org/x/text v0.31.0 // indirect
30+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251124214823-79d6a2a48846 // indirect
31+
google.golang.org/grpc v1.77.0 // indirect
32+
google.golang.org/protobuf v1.36.10 // indirect
33+
)

go.sum

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
cloud.google.com/go/auth v0.17.0 h1:74yCm7hCj2rUyyAocqnFzsAYXgJhrG26XCFimrc/Kz4=
2+
cloud.google.com/go/auth v0.17.0/go.mod h1:6wv/t5/6rOPAX4fJiRjKkJCvswLwdet7G8+UGXt7nCQ=
3+
cloud.google.com/go/auth/oauth2adapt v0.2.8 h1:keo8NaayQZ6wimpNSmW5OPc283g65QNIiLpZnkHRbnc=
4+
cloud.google.com/go/auth/oauth2adapt v0.2.8/go.mod h1:XQ9y31RkqZCcwJWNSx2Xvric3RrU88hAYYbjDWYDL+c=
5+
cloud.google.com/go/compute/metadata v0.9.0 h1:pDUj4QMoPejqq20dK0Pg2N4yG9zIkYGdBtwLoEkH9Zs=
6+
cloud.google.com/go/compute/metadata v0.9.0/go.mod h1:E0bWwX5wTnLPedCKqk3pJmVgCBSM6qQI1yTBdEb3C10=
7+
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
8+
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
9+
github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg=
10+
github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U=
11+
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
12+
github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI=
13+
github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
14+
github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag=
15+
github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE=
16+
github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek=
17+
github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps=
18+
github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
19+
github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
20+
github.com/google/s2a-go v0.1.9 h1:LGD7gtMgezd8a/Xak7mEWL0PjoTQFvpRudN895yqKW0=
21+
github.com/google/s2a-go v0.1.9/go.mod h1:YA0Ei2ZQL3acow2O62kdp9UlnvMmU7kA6Eutn0dXayM=
22+
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
23+
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
24+
github.com/googleapis/enterprise-certificate-proxy v0.3.7 h1:zrn2Ee/nWmHulBx5sAVrGgAa0f2/R35S4DJwfFaUPFQ=
25+
github.com/googleapis/enterprise-certificate-proxy v0.3.7/go.mod h1:MkHOF77EYAE7qfSuSS9PU6g4Nt4e11cnsDUowfwewLA=
26+
github.com/googleapis/gax-go/v2 v2.15.0 h1:SyjDc1mGgZU5LncH8gimWo9lW1DtIfPibOG81vgd/bo=
27+
github.com/googleapis/gax-go/v2 v2.15.0/go.mod h1:zVVkkxAQHa1RQpg9z2AUCMnKhi0Qld9rcmyfL1OZhoc=
28+
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
29+
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
30+
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
31+
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
32+
go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64=
33+
go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y=
34+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 h1:RbKq8BG0FI8OiXhBfcRtqqHcZcka+gU3cskNuf05R18=
35+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0/go.mod h1:h06DGIukJOevXaj/xrNjhi/2098RZzcLTbc0jDAUbsg=
36+
go.opentelemetry.io/otel v1.38.0 h1:RkfdswUDRimDg0m2Az18RKOsnI8UDzppJAtj01/Ymk8=
37+
go.opentelemetry.io/otel v1.38.0/go.mod h1:zcmtmQ1+YmQM9wrNsTGV/q/uyusom3P8RxwExxkZhjM=
38+
go.opentelemetry.io/otel/metric v1.38.0 h1:Kl6lzIYGAh5M159u9NgiRkmoMKjvbsKtYRwgfrA6WpA=
39+
go.opentelemetry.io/otel/metric v1.38.0/go.mod h1:kB5n/QoRM8YwmUahxvI3bO34eVtQf2i4utNVLr9gEmI=
40+
go.opentelemetry.io/otel/sdk v1.38.0 h1:l48sr5YbNf2hpCUj/FoGhW9yDkl+Ma+LrVl8qaM5b+E=
41+
go.opentelemetry.io/otel/sdk v1.38.0/go.mod h1:ghmNdGlVemJI3+ZB5iDEuk4bWA3GkTpW+DOoZMYBVVg=
42+
go.opentelemetry.io/otel/sdk/metric v1.38.0 h1:aSH66iL0aZqo//xXzQLYozmWrXxyFkBJ6qT5wthqPoM=
43+
go.opentelemetry.io/otel/sdk/metric v1.38.0/go.mod h1:dg9PBnW9XdQ1Hd6ZnRz689CbtrUp0wMMs9iPcgT9EZA=
44+
go.opentelemetry.io/otel/trace v1.38.0 h1:Fxk5bKrDZJUH+AMyyIXGcFAPah0oRcT+LuNtJrmcNLE=
45+
go.opentelemetry.io/otel/trace v1.38.0/go.mod h1:j1P9ivuFsTceSWe1oY+EeW3sc+Pp42sO++GHkg4wwhs=
46+
golang.org/x/crypto v0.45.0 h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=
47+
golang.org/x/crypto v0.45.0/go.mod h1:XTGrrkGJve7CYK7J8PEww4aY7gM3qMCElcJQ8n8JdX4=
48+
golang.org/x/net v0.47.0 h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=
49+
golang.org/x/net v0.47.0/go.mod h1:/jNxtkgq5yWUGYkaZGqo27cfGZ1c5Nen03aYrrKpVRU=
50+
golang.org/x/oauth2 v0.33.0 h1:4Q+qn+E5z8gPRJfmRy7C2gGG3T4jIprK6aSYgTXGRpo=
51+
golang.org/x/oauth2 v0.33.0/go.mod h1:lzm5WQJQwKZ3nwavOZ3IS5Aulzxi68dUSgRHujetwEA=
52+
golang.org/x/sync v0.18.0 h1:kr88TuHDroi+UVf+0hZnirlk8o8T+4MrK6mr60WkH/I=
53+
golang.org/x/sync v0.18.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI=
54+
golang.org/x/sys v0.38.0 h1:3yZWxaJjBmCWXqhN1qh02AkOnCQ1poK6oF+a7xWL6Gc=
55+
golang.org/x/sys v0.38.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
56+
golang.org/x/text v0.31.0 h1:aC8ghyu4JhP8VojJ2lEHBnochRno1sgL6nEi9WGFGMM=
57+
golang.org/x/text v0.31.0/go.mod h1:tKRAlv61yKIjGGHX/4tP1LTbc13YSec1pxVEWXzfoeM=
58+
gonum.org/v1/gonum v0.16.0 h1:5+ul4Swaf3ESvrOnidPp4GZbzf0mxVQpDCYUQE7OJfk=
59+
gonum.org/v1/gonum v0.16.0/go.mod h1:fef3am4MQ93R2HHpKnLk4/Tbh/s0+wqD5nfa6Pnwy4E=
60+
google.golang.org/api v0.256.0 h1:u6Khm8+F9sxbCTYNoBHg6/Hwv0N/i+V94MvkOSor6oI=
61+
google.golang.org/api v0.256.0/go.mod h1:KIgPhksXADEKJlnEoRa9qAII4rXcy40vfI8HRqcU964=
62+
google.golang.org/genproto v0.0.0-20250603155806-513f23925822 h1:rHWScKit0gvAPuOnu87KpaYtjK5zBMLcULh7gxkCXu4=
63+
google.golang.org/genproto v0.0.0-20250603155806-513f23925822/go.mod h1:HubltRL7rMh0LfnQPkMH4NPDFEWp0jw3vixw7jEM53s=
64+
google.golang.org/genproto/googleapis/api v0.0.0-20251022142026-3a174f9686a8 h1:mepRgnBZa07I4TRuomDE4sTIYieg/osKmzIf4USdWS4=
65+
google.golang.org/genproto/googleapis/api v0.0.0-20251022142026-3a174f9686a8/go.mod h1:fDMmzKV90WSg1NbozdqrE64fkuTv6mlq2zxo9ad+3yo=
66+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251124214823-79d6a2a48846 h1:Wgl1rcDNThT+Zn47YyCXOXyX/COgMTIdhJ717F0l4xk=
67+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251124214823-79d6a2a48846/go.mod h1:7i2o+ce6H/6BluujYR+kqX3GKH+dChPTQU19wjRPiGk=
68+
google.golang.org/grpc v1.77.0 h1:wVVY6/8cGA6vvffn+wWK5ToddbgdU3d8MNENr4evgXM=
69+
google.golang.org/grpc v1.77.0/go.mod h1:z0BY1iVj0q8E1uSQCjL9cppRj+gnZjzDnzV0dHhrNig=
70+
google.golang.org/protobuf v1.36.10 h1:AYd7cD/uASjIL6Q9LiTjz8JLcrh/88q5UObnmY3aOOE=
71+
google.golang.org/protobuf v1.36.10/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
72+
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
73+
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=

main.go

Lines changed: 29 additions & 94 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,6 @@ package main
22

33
import (
44
"context"
5-
"encoding/json"
65
"fmt"
76
"log/slog"
87
"net/http"
@@ -14,6 +13,10 @@ import (
1413
"sync"
1514
"syscall"
1615
"time"
16+
17+
"golang.org/x/oauth2/google"
18+
compute "google.golang.org/api/compute/v1"
19+
"google.golang.org/api/option"
1720
)
1821

1922
type Config struct {
@@ -26,16 +29,6 @@ type Config struct {
2629
GCEInstance string
2730
}
2831

29-
type AccessToken struct {
30-
AccessToken string `json:"access_token"`
31-
ExpiresIn int `json:"expires_in"`
32-
TokenType string `json:"token_type"`
33-
}
34-
35-
type ComputeInstance struct {
36-
Status string `json:"status"`
37-
}
38-
3932
type ActivityTracker struct {
4033
mu sync.RWMutex
4134
requestCount int64
@@ -162,115 +155,57 @@ func getLastGitHubActionsActivity() (time.Time, error) {
162155
return time.Time{}, fmt.Errorf("could not parse github-actions timestamp")
163156
}
164157

165-
func getAccessToken() (AccessToken, error) {
166-
t := AccessToken{}
167-
168-
req, err := http.NewRequest("GET", "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token", nil)
158+
func createComputeService(ctx context.Context) (*compute.Service, error) {
159+
// Use Application Default Credentials (ADC)
160+
// This will automatically use:
161+
// 1. GOOGLE_APPLICATION_CREDENTIALS environment variable
162+
// 2. GCE metadata server (when running on GCE)
163+
// 3. gcloud CLI credentials
164+
creds, err := google.FindDefaultCredentials(ctx, compute.ComputeScope)
169165
if err != nil {
170-
return t, err
166+
return nil, fmt.Errorf("failed to find default credentials: %w", err)
171167
}
172-
req.Header.Set("Metadata-Flavor", "Google")
173168

174-
client := &http.Client{Timeout: 10 * time.Second}
175-
resp, err := client.Do(req)
169+
service, err := compute.NewService(ctx, option.WithCredentials(creds))
176170
if err != nil {
177-
return t, err
178-
}
179-
defer resp.Body.Close()
180-
181-
if resp.StatusCode != http.StatusOK {
182-
return t, fmt.Errorf("fetching token non-200: %d", resp.StatusCode)
171+
return nil, fmt.Errorf("failed to create compute service: %w", err)
183172
}
184173

185-
if err := json.NewDecoder(resp.Body).Decode(&t); err != nil {
186-
return t, fmt.Errorf("failed to decode token response: %w", err)
187-
}
188-
return t, nil
189-
}
190-
191-
func getMachineMetadata(token AccessToken, targetURL string) (ComputeInstance, error) {
192-
vm := ComputeInstance{}
193-
194-
req, err := http.NewRequest("GET", targetURL, nil)
195-
if err != nil {
196-
return vm, err
197-
}
198-
req.Header.Set("Authorization", "Bearer "+token.AccessToken)
199-
200-
client := &http.Client{Timeout: 30 * time.Second}
201-
resp, err := client.Do(req)
202-
if err != nil {
203-
return vm, err
204-
}
205-
defer resp.Body.Close()
206-
207-
if resp.StatusCode != http.StatusOK {
208-
return vm, fmt.Errorf("getMachineMetadata non-200: %d", resp.StatusCode)
209-
}
210-
211-
if err := json.NewDecoder(resp.Body).Decode(&vm); err != nil {
212-
return vm, fmt.Errorf("failed to decode instance metadata: %w", err)
213-
}
214-
return vm, nil
215-
}
216-
217-
func performInstanceAction(token AccessToken, targetURL, action string) error {
218-
actionURL := targetURL + "/" + action
219-
220-
req, err := http.NewRequest("POST", actionURL, nil)
221-
if err != nil {
222-
return err
223-
}
224-
req.Header.Set("Authorization", "Bearer "+token.AccessToken)
225-
226-
client := &http.Client{Timeout: 30 * time.Second}
227-
resp, err := client.Do(req)
228-
if err != nil {
229-
return err
230-
}
231-
defer resp.Body.Close()
232-
233-
if resp.StatusCode != http.StatusOK {
234-
return fmt.Errorf("performInstanceAction non-200: %d", resp.StatusCode)
235-
}
236-
237-
return nil
174+
return service, nil
238175
}
239176

240-
func suspendMachine() (ComputeInstance, error) {
241-
targetURL := fmt.Sprintf("https://compute.googleapis.com/compute/v1/projects/%s/zones/%s/instances/%s",
242-
config.GoogleProjectID, config.GCEZone, config.GCEInstance)
177+
func suspendMachine() (*compute.Instance, error) {
178+
ctx := context.Background()
243179

244180
slog.Info("Checking if machine is suspended",
245181
"project", config.GoogleProjectID,
246182
"zone", config.GCEZone,
247183
"instance", config.GCEInstance)
248184

249-
// get access token
250-
t, err := getAccessToken()
185+
// Create compute service with default credentials
186+
service, err := createComputeService(ctx)
251187
if err != nil {
252-
return ComputeInstance{}, fmt.Errorf("getAccessToken: %v", err)
188+
return nil, fmt.Errorf("createComputeService: %v", err)
253189
}
254190

255-
// get machine metadata
256-
vm, err := getMachineMetadata(t, targetURL)
191+
// Get instance details
192+
instance, err := service.Instances.Get(config.GoogleProjectID, config.GCEZone, config.GCEInstance).Context(ctx).Do()
257193
if err != nil {
258-
return vm, fmt.Errorf("getMachineMetadata: %v", err)
194+
return nil, fmt.Errorf("failed to get instance: %v", err)
259195
}
260196

261-
// if the machine is running, suspend it
262-
if vm.Status == "RUNNING" {
263-
action := "suspend"
197+
// If the machine is running, suspend it
198+
if instance.Status == "RUNNING" {
264199
slog.Info("Instance is RUNNING, suspending instance")
265-
err := performInstanceAction(t, targetURL, action)
200+
_, err := service.Instances.Suspend(config.GoogleProjectID, config.GCEZone, config.GCEInstance).Context(ctx).Do()
266201
if err != nil {
267-
return vm, fmt.Errorf("performInstanceAction: %v", err)
202+
return instance, fmt.Errorf("failed to suspend instance: %v", err)
268203
}
269204
} else {
270-
slog.Info("Instance is not RUNNING, skipping suspension", "status", vm.Status)
205+
slog.Info("Instance is not RUNNING, skipping suspension", "status", instance.Status)
271206
}
272207

273-
return vm, nil
208+
return instance, nil
274209
}
275210

276211
func suspendInstance() error {

0 commit comments

Comments
 (0)