compute.go raw

   1  // Copyright 2023 Google LLC
   2  //
   3  // Licensed under the Apache License, Version 2.0 (the "License");
   4  // you may not use this file except in compliance with the License.
   5  // You may obtain a copy of the License at
   6  //
   7  //      http://www.apache.org/licenses/LICENSE-2.0
   8  //
   9  // Unless required by applicable law or agreed to in writing, software
  10  // distributed under the License is distributed on an "AS IS" BASIS,
  11  // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12  // See the License for the specific language governing permissions and
  13  // limitations under the License.
  14  
  15  package credentials
  16  
  17  import (
  18  	"context"
  19  	"encoding/json"
  20  	"errors"
  21  	"fmt"
  22  	"net/url"
  23  	"strings"
  24  	"time"
  25  
  26  	"cloud.google.com/go/auth"
  27  	"cloud.google.com/go/compute/metadata"
  28  )
  29  
  30  var (
  31  	computeTokenMetadata = map[string]interface{}{
  32  		"auth.google.tokenSource":    "compute-metadata",
  33  		"auth.google.serviceAccount": "default",
  34  	}
  35  	computeTokenURI = "instance/service-accounts/default/token"
  36  )
  37  
  38  // computeTokenProvider creates a [cloud.google.com/go/auth.TokenProvider] that
  39  // uses the metadata service to retrieve tokens.
  40  func computeTokenProvider(opts *DetectOptions, client *metadata.Client) auth.TokenProvider {
  41  	return auth.NewCachedTokenProvider(&computeProvider{
  42  		scopes:           opts.Scopes,
  43  		client:           client,
  44  		tokenBindingType: opts.TokenBindingType,
  45  	}, &auth.CachedTokenProviderOptions{
  46  		ExpireEarly:         opts.EarlyTokenRefresh,
  47  		DisableAsyncRefresh: opts.DisableAsyncRefresh,
  48  	})
  49  }
  50  
  51  // computeProvider fetches tokens from the google cloud metadata service.
  52  type computeProvider struct {
  53  	scopes           []string
  54  	client           *metadata.Client
  55  	tokenBindingType TokenBindingType
  56  }
  57  
  58  type metadataTokenResp struct {
  59  	AccessToken  string `json:"access_token"`
  60  	ExpiresInSec int    `json:"expires_in"`
  61  	TokenType    string `json:"token_type"`
  62  }
  63  
  64  func (cs *computeProvider) Token(ctx context.Context) (*auth.Token, error) {
  65  	tokenURI, err := url.Parse(computeTokenURI)
  66  	if err != nil {
  67  		return nil, err
  68  	}
  69  	hasScopes := len(cs.scopes) > 0
  70  	if hasScopes || cs.tokenBindingType != NoBinding {
  71  		v := url.Values{}
  72  		if hasScopes {
  73  			v.Set("scopes", strings.Join(cs.scopes, ","))
  74  		}
  75  		switch cs.tokenBindingType {
  76  		case MTLSHardBinding:
  77  			v.Set("transport", "mtls")
  78  			v.Set("binding-enforcement", "on")
  79  		case ALTSHardBinding:
  80  			v.Set("transport", "alts")
  81  		}
  82  		tokenURI.RawQuery = v.Encode()
  83  	}
  84  	tokenJSON, err := cs.client.GetWithContext(ctx, tokenURI.String())
  85  	if err != nil {
  86  		return nil, fmt.Errorf("credentials: cannot fetch token: %w", err)
  87  	}
  88  	var res metadataTokenResp
  89  	if err := json.NewDecoder(strings.NewReader(tokenJSON)).Decode(&res); err != nil {
  90  		return nil, fmt.Errorf("credentials: invalid token JSON from metadata: %w", err)
  91  	}
  92  	if res.ExpiresInSec == 0 || res.AccessToken == "" {
  93  		return nil, errors.New("credentials: incomplete token received from metadata")
  94  	}
  95  	token := &auth.Token{
  96  		Value:    res.AccessToken,
  97  		Type:     res.TokenType,
  98  		Expiry:   time.Now().Add(time.Duration(res.ExpiresInSec) * time.Second),
  99  		Metadata: computeTokenMetadata,
 100  	}
 101  	return token, nil
 102  }
 103