Skip to content

Allow raw JSON to be passed into GOOGLE_APPLICATION_CREDENTIALS env variable #323

Description

@mholyak

... or into new env variable.

Usecase is using service in bitbucket pipelines:

image

Activity

  1. added
    type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.
    on Oct 28, 2019
  2. kurtisvg commented on Oct 28, 2019

    @kurtisvg
    Contributor

    While this isn't the exact useless you described, you can use the -token flag to pass in credentials to the proxy when it starts (which could rely on a env var).

  3. Carrotman42 commented on Oct 28, 2019

    @Carrotman42
    Contributor
  4. Carrotman42 commented on Oct 28, 2019

    @Carrotman42
    Contributor
  5. mholyak commented on Oct 28, 2019

    @mholyak
    Author

    Is there a way to store a file to disk using the bitbucket configuration?

    Sure, and I'm using it now to run cloud-proxy in background:

    image

    But, if I want to have it as stand-alone service (similar to docker-compose items) I need to define it in special separate section and only env variables are available there...

  6. gregmsanderson commented on Apr 9, 2020

    @gregmsanderson

    +1 for this, seems like a great idea to be able to pass the json content. Since many faas/paas seem to support using secrets in key => value form. So then the content of the json could be stored once, as a secret, and then that file then never needs to be kept in a file system.

  7. ryboe commented on Apr 13, 2020

    @ryboe

    +1 for this. Requiring that the file be present on the filesystem makes cloud_sql_proxy difficult to use with terraform. This code search of GitHub shows that the only way anybody has figured out how to deploy cloud_sql_proxy with terraform is to use k8s volume mounts.

    I think the scarcity of terraform+cloud_sql_proxy usage on GitHub points to a serious usability problem. It is, of course, up to you whether you want to support terraform. If you do, allowing us to set the entire service account key as an env var would make cloud_sql_proxy much easier to use. Thanks for keeping this issue open and considering this feature.

  8. added
    priority: p3Desirable enhancement or fix. May not be included in next release.
    on Feb 9, 2021
  9. enocom commented on Sep 14, 2022

    @enocom
    Member

    We don’t control GOOGLE_APPLICATION_CREDENTIALS and so can’t change how it works. However, there is a CredentialsFromJSON method that we could in theory expose as a CLI flag. That said I don’t understand the use case here and why using a credential file isn’t a reasonable option.

  10. ryboe commented on Sep 15, 2022

    @ryboe

    The use case is: it's easier to pass the credentials into a container as an env var instead of mounting them as a volume. Look at all the templating hoops I had to jump through to deploy Cloud SQL Proxy with Terraform. Also, lots of container environments are restricted (e.g. CI/CD) and don't let you mount volumes. But just about every container environment lets you set env vars.

  11. added
    priority: p0Highest priority. Critical issue. P0 implies highest priority.
    and removed
    priority: p3Desirable enhancement or fix. May not be included in next release.
    on Sep 15, 2022
  12. enocom commented on Sep 15, 2022

    @enocom
    Member

    Thanks @ryboe. That makes perfect sense. This is such an easy and quick change, I'll pull it into my queue.

  13. self-assigned this
    on Sep 15, 2022
  14. added 2 commits that reference this issue on Sep 19, 2022
    7f2ba2d
    5803ad6
  15. added a commit that references this issue on Sep 23, 2022
    2a9c8d8
  16. enocom commented on Sep 24, 2022

    @enocom
    Member

    This is on main now and will be available in the next preview release of v2 (preview 2).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

priority: p0Highest priority. Critical issue. P0 implies highest priority.type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions