Skip to content

Support for --impersonate-service-account #417

Description

@xanonid

It would be nice, if Cloud SQL Proxy supports the --impersonate-service-account flag similar to the corresponding flag in gcloud. This would help to use impersonation out-of-the-box instead of long-running and possibly non-personalized service-account credentials.

Activity

  1. added
    type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.
    on Jul 15, 2020
  2. added
    priority: p3Desirable enhancement or fix. May not be included in next release.
    on Jul 15, 2020
  3. removed their assignment
    on Feb 26, 2021
  4. red8888 commented on May 4, 2021

    @red8888

    any movement on this? Is it even possible to use impersonation with cloud_sql_proxy? Im not generating static non-expiring keys for my service accounts

  5. kurtisvg commented on May 4, 2021

    @kurtisvg
    Contributor

    It looks like the SQLAdmin client provides a hook for doing this now: https://pkg.go.dev/google.golang.org/api/option#ImpersonateCredentials

  6. red8888 commented on Sep 2, 2021

    @red8888

    Is there any updates or status on this? The only way I have been able to impersonate is with gcloud via gcloud config set auth/impersonate_service_account <MY_SERVICE_ACCOUNT>

    The support for this is so poor. Can I run gcloud auth print-access-token --impersonate-service-account=<MY_SERVICE_ACCOUNT> and set an env var to the access token or something?

  7. added
    priority: p2Moderately-important priority. Fix may not be included in next release.
    and removed
    priority: p3Desirable enhancement or fix. May not be included in next release.
    on Sep 7, 2021
  8. enocom commented on Sep 7, 2021

    @enocom
    Member

    Bumping up the priority on this. Right now there's not a good built-in way to do this.

    For people who didn't see the StackOverflow post, a current workaround looks like this:

    cloud_sql_proxy --instances=<instanceName>=tcp:3306 \
      --token=$(gcloud auth print-access-token --impersonate-service-account=<service account>)
    
  9. enocom commented on Sep 10, 2021

    @enocom
    Member

    We're presently working on a v2 of the proxy, which will include a new dialer as well. We plan to add support for impersonating an account there (see the tracking issue linked above for progress).

  10. 2 remaining items

  11. added
    priority: p1Important issue which blocks shipping the next release. Will be fixed prior to next release.
    and removed
    priority: p2Moderately-important priority. Fix may not be included in next release.
    on Aug 31, 2022
  12. enocom commented on Aug 31, 2022

    @enocom
    Member

    Yes, we will support this in v2. With the new Go Connector this is an easy fix.

  13. enocom commented on Aug 31, 2022

    @enocom
    Member

    Looking at this again, there's a new API that will return a token source with impersonated credentials.

    https://pkg.go.dev/google.golang.org/[email protected]/impersonate

    So in effect, we'd just need to expose some CLI flags to configure that token source and be good.

  14. enocom commented on Sep 12, 2022

    @enocom
    Member

    Thinking about CLI flags, I think the proxy would only need to expose TargetPrincipal and Delegates here: https://pkg.go.dev/google.golang.org/[email protected]/impersonate#CredentialsConfig.

    The proxy knows the necessary Scopes. Lifetime has a good default. And Subject seems unnecessary for our use case here.

  15. added
    priority: p0Highest priority. Critical issue. P0 implies highest priority.
    and removed
    priority: p1Important issue which blocks shipping the next release. Will be fixed prior to next release.
    on Sep 12, 2022
  16. enocom commented on Sep 12, 2022

    @enocom
    Member

    Bumping the priority up since there's a lot of interest here.

  17. self-assigned this
    on Sep 24, 2022
  18. added 3 commits that reference this issue on Oct 7, 2022
    64e4987
    abe1d79
    bf71026
  19. added a commit that references this issue on Oct 14, 2022
    d0f8e55
  20. enocom commented on Oct 14, 2022

    @enocom
    Member

    We'll have this in the next release which we'll cut before next month.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

priority: p0Highest priority. Critical issue. P0 implies highest priority.type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions