【发布时间】:2021-06-10 19:53:42
【问题描述】:
我正在使用 Go 语言中的 Google Cloud 并关注 John Hanley 的这篇文章:
https://www.jhanley.com/google-cloud-improving-security-with-impersonation/
并用这个 SO 答案将其捣碎:
凭据已成功保存到“application_default_credentials.json”:
注意:“type”:“impersonated_service_account”
{
"delegates": [],
"service_account_impersonation_url": "https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/[sa@example-2021.iam.gserviceaccount.com]:generateAccessToken",
"source_credentials": {
"client_id": "...apps.googleusercontent.com",
"client_secret": "...",
"refresh_token": "...",
"type": "authorized_user"
},
"type": "impersonated_service_account"
}
我的代码产生 unknown credential type: "impersonated_service_account" 错误:
package main
import (
...
"cloud.google.com/go/storage"
"golang.org/x/oauth2"
"google.golang.org/api/docs/v1"
"google.golang.org/api/drive/v3"
"google.golang.org/api/impersonate"
"google.golang.org/api/option"
...
)
var Config.GoogleServiceAccount string = "sa@example-2021.iam.gserviceaccount.com"
func main(){
_ = getTokenAsImpersonator()
}
// From: https://pkg.go.dev/google.golang.org/api/impersonate#example-CredentialsTokenSource-ServiceAccount
func getTokenAsImpersonator() oauth2.TokenSource {
ctx := context.Background()
// Base credentials sourced from ADC or provided client options.
ts, err := impersonate.CredentialsTokenSource(ctx, impersonate.CredentialsConfig{
TargetPrincipal: Config.GoogleServiceAccount,
Scopes: []string{"https://www.googleapis.com/auth/cloud-platform"},
// Delegates: []string{"bar@project-id.iam.gserviceaccount.com"},
})
if err != nil {
log.Fatal(err)
}
return ts
}
“未知凭据类型:“impersonated_service_account”'错误:
google: error getting credentials using GOOGLE_APPLICATION_CREDENTIALS environment variable: unknown credential type: "impersonated_service_account"
我做错了什么还是这是一个错误?
更新
回答来自 cmets 的 John 的问题:
1.
a) GOOGLE_APPLICATION_CREDENTIALS 环境变量的值是多少?
GOOGLE_APPLICATION_CREDENTIALS=/Users/x/.config/gcloud/application_default_credentials.json
b) 您使用什么命令生成 application_default_credentials.json?
gcloud auth application-default login --scopes=https://www.googleapis.com/auth/drive,https://www.googleapis.com/auth/userinfo.email,https://www.googleapis.com/auth/cloud-platform,https://www.googleapis.com/auth/accounts.reauth,openid --impersonate-service-account=[sa@example-2021.iam.gserviceaccount.com]
Response:
Credentials saved to file: [/Users/x/.config/gcloud/application_default_credentials.json]
c)哪个操作系统和版本?
MacOS 10.13.6
d)gcloud --version?
Google Cloud SDK 343.0.0
app-engine-go
app-engine-python 1.9.91
bq 2.0.69
cloud-datastore-emulator 2.1.0
core 2021.05.27
gsutil 4.62
- 如果您可以创建一个最小示例...
我已经更新了上面的示例代码。
【问题讨论】:
-
使用这些详细信息更新您的问题。 a) 环境变量
GOOGLE_APPLICATION_CREDENTIALS的值是多少? b) 你用什么命令生成application_default_credentials.json? c:) 哪个操作系统和版本? d)gcloud --version2) 如果您可以创建一个最小示例以便我可以在我的系统上重现它,我将帮助您完成此工作。是时候为我的文章添加新的细节了。 -
我没有看到来自 google 的任何“impersonated_service_account”搜索结果,只有“impersonate_service_account”。你能分享关于这个@JohnHanley 的任何信息吗?我对这个话题不太熟悉,但很感兴趣。
-
@NaziA - 我还没有解决这个问题。我确实相信
impersonated_service_account是 CLI 存储的凭证类型。大多数情况下,用户不应直接访问application_default_credentials.json。 SDK 中的core/credentials/creds.py是函数_ConvertCredentialsToADC(),用于转换此凭证。我打算从了解这个功能开始。 -
@NaziA - 另一个重要的项目是
IMPERSONATION_TOKEN_URL = 'https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/{}:generateAccessToken'模拟创建的令牌用作调用该 URL 以获取正常访问令牌的授权。我通过使用 Google Workload Identity Federation 了解了这些细节。一旦我将模拟和联合联系在一起,我应该知道底层细节。
标签: go authentication google-cloud-platform google-drive-api google-docs-api