I want to build a client gcp tool in python.
I want to avoid invocations of the glcoud tool via subprocess so I opt for sdk client library invocations.
According to the docs as also this very and comprehensive article, there are two options for auth:
a) using the application default credentials (i.e. the ones used by gcloud under the hood)
b) using a service account and pointing the app to the corresponding .json file.
I have already tried the (a) and got the following warning:
UserWarning: Your application has authenticated using end user credentials from Google Cloud SDK. We recommend that most server applications use service accounts instead. If your application continues to use end user credentials from Cloud SDK, you might receive a "quota exceeded" or "API not enabled" error. For more information about service accounts, see https://cloud.google.com/docs/authentication/
warnings.warn(_CLOUD_SDK_CREDENTIALS_WARNING)
If I use app default creds, this makes it easy since each end user the app will be distributed to, will have this .json file a source of truth for his/her auth process. However, the app may encounter the above quota exceeded error.
In the other case, (service account specific credentials) I assume I will have to provide instructions to each developer to issue a json file that corresponds to a service account with the exact same permission as his/hers. And what about the update process? What happens each time a user gets assigned / revoked some permissions? How this json stays in sync?
Any advice about this would be highly appreciated.