compute.go raw
1 // Copyright 2023 Google LLC
2 //
3 // Licensed under the Apache License, Version 2.0 (the "License");
4 // you may not use this file except in compliance with the License.
5 // You may obtain a copy of the License at
6 //
7 // http://www.apache.org/licenses/LICENSE-2.0
8 //
9 // Unless required by applicable law or agreed to in writing, software
10 // distributed under the License is distributed on an "AS IS" BASIS,
11 // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 // See the License for the specific language governing permissions and
13 // limitations under the License.
14
15 package credentials
16
17 import (
18 "context"
19 "encoding/json"
20 "errors"
21 "fmt"
22 "net/url"
23 "strings"
24 "time"
25
26 "cloud.google.com/go/auth"
27 "cloud.google.com/go/compute/metadata"
28 )
29
30 var (
31 computeTokenMetadata = map[string]interface{}{
32 "auth.google.tokenSource": "compute-metadata",
33 "auth.google.serviceAccount": "default",
34 }
35 computeTokenURI = "instance/service-accounts/default/token"
36 )
37
38 // computeTokenProvider creates a [cloud.google.com/go/auth.TokenProvider] that
39 // uses the metadata service to retrieve tokens.
40 func computeTokenProvider(opts *DetectOptions, client *metadata.Client) auth.TokenProvider {
41 return auth.NewCachedTokenProvider(&computeProvider{
42 scopes: opts.Scopes,
43 client: client,
44 tokenBindingType: opts.TokenBindingType,
45 }, &auth.CachedTokenProviderOptions{
46 ExpireEarly: opts.EarlyTokenRefresh,
47 DisableAsyncRefresh: opts.DisableAsyncRefresh,
48 })
49 }
50
51 // computeProvider fetches tokens from the google cloud metadata service.
52 type computeProvider struct {
53 scopes []string
54 client *metadata.Client
55 tokenBindingType TokenBindingType
56 }
57
58 type metadataTokenResp struct {
59 AccessToken string `json:"access_token"`
60 ExpiresInSec int `json:"expires_in"`
61 TokenType string `json:"token_type"`
62 }
63
64 func (cs *computeProvider) Token(ctx context.Context) (*auth.Token, error) {
65 tokenURI, err := url.Parse(computeTokenURI)
66 if err != nil {
67 return nil, err
68 }
69 hasScopes := len(cs.scopes) > 0
70 if hasScopes || cs.tokenBindingType != NoBinding {
71 v := url.Values{}
72 if hasScopes {
73 v.Set("scopes", strings.Join(cs.scopes, ","))
74 }
75 switch cs.tokenBindingType {
76 case MTLSHardBinding:
77 v.Set("transport", "mtls")
78 v.Set("binding-enforcement", "on")
79 case ALTSHardBinding:
80 v.Set("transport", "alts")
81 }
82 tokenURI.RawQuery = v.Encode()
83 }
84 tokenJSON, err := cs.client.GetWithContext(ctx, tokenURI.String())
85 if err != nil {
86 return nil, fmt.Errorf("credentials: cannot fetch token: %w", err)
87 }
88 var res metadataTokenResp
89 if err := json.NewDecoder(strings.NewReader(tokenJSON)).Decode(&res); err != nil {
90 return nil, fmt.Errorf("credentials: invalid token JSON from metadata: %w", err)
91 }
92 if res.ExpiresInSec == 0 || res.AccessToken == "" {
93 return nil, errors.New("credentials: incomplete token received from metadata")
94 }
95 token := &auth.Token{
96 Value: res.AccessToken,
97 Type: res.TokenType,
98 Expiry: time.Now().Add(time.Duration(res.ExpiresInSec) * time.Second),
99 Metadata: computeTokenMetadata,
100 }
101 return token, nil
102 }
103