Repository navigation
Support for --impersonate-service-account #417
Description
Activity
- addedtype: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.‘Nice-to-have’ improvement, new feature or different behavior or design.
on Jul 15, 2020 - addedpriority: p3Desirable enhancement or fix. May not be included in next release.Desirable enhancement or fix. May not be included in next release.
on Jul 15, 2020 any movement on this? Is it even possible to use impersonation with cloud_sql_proxy? Im not generating static non-expiring keys for my service accounts
Reacted by rd-michel and MichalIt looks like the SQLAdmin client provides a hook for doing this now: https://pkg.go.dev/google.golang.org/api/option#ImpersonateCredentials
Is there any updates or status on this? The only way I have been able to impersonate is with gcloud via
gcloud config set auth/impersonate_service_account <MY_SERVICE_ACCOUNT>The support for this is so poor. Can I run
gcloud auth print-access-token --impersonate-service-account=<MY_SERVICE_ACCOUNT>and set an env var to the access token or something?- addedpriority: p2Moderately-important priority. Fix may not be included in next release.Moderately-important priority. Fix may not be included in next release.and removedpriority: p3Desirable enhancement or fix. May not be included in next release.Desirable enhancement or fix. May not be included in next release.
on Sep 7, 2021 Bumping up the priority on this. Right now there's not a good built-in way to do this.
For people who didn't see the StackOverflow post, a current workaround looks like this:
cloud_sql_proxy --instances=<instanceName>=tcp:3306 \ --token=$(gcloud auth print-access-token --impersonate-service-account=<service account>)We're presently working on a v2 of the proxy, which will include a new dialer as well. We plan to add support for impersonating an account there (see the tracking issue linked above for progress).
Reacted by Marius Kießling, Jonathan Yu, Hannes Hayashi and benorgil2 remaining items
- addedpriority: p1Important issue which blocks shipping the next release. Will be fixed prior to next release.Important issue which blocks shipping the next release. Will be fixed prior to next release.and removedpriority: p2Moderately-important priority. Fix may not be included in next release.Moderately-important priority. Fix may not be included in next release.
on Aug 31, 2022 Yes, we will support this in v2. With the new Go Connector this is an easy fix.
Reacted by Jonas Hedman Engström and Hannes HayashiLooking at this again, there's a new API that will return a token source with impersonated credentials.
https://pkg.go.dev/google.golang.org/[email protected]/impersonate
So in effect, we'd just need to expose some CLI flags to configure that token source and be good.
Reacted by Jonas Hedman Engström, Hannes Hayashi, Fuyang Liu and Jonathan YuThinking about CLI flags, I think the proxy would only need to expose
TargetPrincipalandDelegateshere: https://pkg.go.dev/google.golang.org/[email protected]/impersonate#CredentialsConfig.The proxy knows the necessary
Scopes.Lifetimehas a good default. AndSubjectseems unnecessary for our use case here.- addedpriority: p0Highest priority. Critical issue. P0 implies highest priority.Highest priority. Critical issue. P0 implies highest priority.and removedpriority: p1Important issue which blocks shipping the next release. Will be fixed prior to next release.Important issue which blocks shipping the next release. Will be fixed prior to next release.
on Sep 12, 2022 Bumping the priority up since there's a lot of interest here.
Reacted by Hannes Hayashi, Rob Zwissler and Tuan Anh Pham- added 3 commits that reference this issue
on Oct 7, 2022 - added a commit that references this issue
on Oct 14, 2022 We'll have this in the next release which we'll cut before next month.
It would be nice, if Cloud SQL Proxy supports the
--impersonate-service-accountflag similar to the corresponding flag ingcloud. This would help to use impersonation out-of-the-box instead of long-running and possibly non-personalized service-account credentials.