Goal:
Generate signed URLs inside GKE pods without manually injecting a service account JSON key. The syntax for generating them requires a service account email and private key.
//import "cloud.google.com/go/storage"
url, err := storage.SignedURL(bucketName, objectName, &storage.SignedURLOptions{
ContentType: contentType,
GoogleAccessID: saEmail,
PrivateKey: saPrivateKey,
})
In other words, I'd like to load saEmail and saPrivateKey from the default credentials automatically available in GKE nodes.
Attempt:
ctx := context.Background()
//errors ignored for brevity
//import "golang.org/x/oauth2/google"
creds, _ := google.FindDefaultCredentials(ctx, storage.ScopeReadWrite)
cfg, _ := google.JWTConfigFromJSON(creds.JSON)
url, _ := storage.SignedURL(bucketName, objectName, &storage.SignedURLOptions{
ContentType: contentType,
GoogleAccessID: cfg.Email,
PrivateKey: cfg.PrivateKey,
})
When I ran google.FindDefaultCredentials() inside a GKE pod, the result JSON is empty.
Environment:
Go1.13GKE1.14.10-gke.36cloud.google.com/gov0.58.0cloud.google.com/go/storagev1.8.0
Additional Notes:
I've tested two possible alternatives involving injecting the service account key (JSON) manually into the pod, but I hope to avoid them if possible:
Writing the service account key into a file and setting
GOOGLE_APPLICATION_CREDENTIALSto its path. When this is done,google.FindDefaultCredentials()loads the email and private key.Passing the service account key as a string into the pod and parsing it with
google.JWTConfigFromJSON().