Is it possible to access a service account credentials from a container built and started by a GCB step?

Viewed 763

To run integration tests we build and start a new container in one GCB's step:

- name: 'gcr.io/google.com/cloudsdktool/cloud-sdk'
  entrypoint: 'gcloud'
  args: ['container', 'clusters', 'get-credentials', '$_GC_CLUSTER', '--zone', '$_GC_ZONE']
- name: 'nixery.dev/bash/...'
  entrypoint: 'make' # test creates and runs a new container
  args: ['test', '-C', '$_SERVICE']

Of course, this new container doesn't have access to the default account service of GCB, so it cannot access other resources like Google Cloud Storage.

We could include another service account credentials in the base image, but it would be better if we could rely on the credentials provided by GCB. I tried copying the Kubernetes configuration and the Google Cloud SDK configuration from the parent container, but it doesn't work so I guess I'm on the wrong path.

This answer mentions using --impersonate-service-account with gcloud auth configure-docker, but it doesn't give more details. I'm running the previous command in the container I want to grant access to just before running the tests:

gcloud auth configure-docker --impersonate-service-account project-number-compute@developer.gserviceaccount.com

python3 -m pytest tests

But I still get an authentication error. If it is possible, what am I missing?

2 Answers

The container needs to be in the cloudbuild network. When you build it, specify --network=cloudbuild

See Google Cloud Build network.

I have a solution. Not sure that is the most elegant one, but it works

  1. Get the authentication from the cluster
  2. Save the authentication into the only folder which is kept from 1 step to another one /workspace (or the current one in my example)
  3. Copy the saved authentication in the home dir of the next step
        - name: gcr.io/cloud-builders/gcloud
          entrypoint: "bash"
          args:
            - "-c"
            - |
                    gcloud container clusters get-credentials cluster-1 --zone us-central1-c 
                    cp -r ~/.kube ./.kube
                    ls -la .kube/
        - name: gcr.io/cloud-builders/gcloud
          entrypoint: "bash"
          args:
            - "-c"
            - |
                    cp -r ./.kube ~/.kube
                    kubectl get all

Here 2 times the gcloud builder, but it doesn't matter

Related