Skip to content

fix(google): default external account credential format to text - #910

Merged
Xuanwo merged 1 commit into
mainfrom
xuanwo/fix-google-external-account-format
Oct 8, 2026
Merged

Xuanwo merged 1 commit into
mainfrom
xuanwo/fix-google-external-account-format

Conversation

@Xuanwo

@Xuanwo Xuanwo commented Oct 7, 2026

Copy link
Copy Markdown
Member

External account credential files generated by gcloud can omit credential_source.format. Reqsign currently rejects those files, allowing the default credential chain to fall back to VM metadata instead of using the configured identity.

Default omitted formats to plain text for both file and URL sources, as required by AIP-4117. Explicit text and JSON formats retain their existing behavior, and malformed explicit formats remain errors.

The regression test exercises GOOGLE_APPLICATION_CREDENTIALS through the default provider, verifies the subject token sent to mocked STS, and rejects metadata fallback. It reproduced the fallback before the fix and passes afterward for both source types; live cloud exchange was not tested.

Fixes #909.

@Xuanwo
Xuanwo marked this pull request as ready for review October 7, 2026 16:32
@Xuanwo
Xuanwo merged commit 92dd018 into main Oct 8, 2026
64 checks passed
@Xuanwo
Xuanwo deleted the xuanwo/fix-google-external-account-format branch October 8, 2026 14:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

reqsign-google: external_account configs without credential_source.format fail to parse (Google defaults it to text)

1 participant