I have done the below and it all works to the point of the last token being used to invoke a cloud function.
I have created a service account (SP), in Project 2, with Service-Account-Token-Creator and Cloud-Functions-Invoker roles. I also have created another service account (sc), in Project 1, with Service-Account-Token-Creator. I edited the IAM bindings of SP to allow SC the ability to create short-lived credentials via the Service-Account-Token-Creator role.
This code below, in Project 1, is running on CloudRun and with the service account, SC as the default service account for the instance.
Not sure what is really wrong, but all I'm trying to do is impersonate SP and then be able to invoke the cloud function in SP's account.
Any assistance with what is going wrong would help.
import { Compute } from 'google-auth-library';
const client = new Compute({
// Specifying the service account email is optional.
serviceAccountEmail:
'sc@swaymeebusinessapp.iam.gserviceaccount.com',
});
const res = await client.request<{
accessToken: string;
expireTime: string;
}>({
url:
'https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/sp@<project-di>.iam.gserviceaccount.com:generateAccessToken',
method: 'POST',
data: JSON.stringify({
delegates: [],
scope: ['https://www.googleapis.com/auth/cloud-platform'],
lifetime: '300s',
}),
});
request.http.headers.set(
'Authorization',
`Bearer ${res.data.accessToken}`
);
The error I received when invoking the cloud function in project 2 is
https://us-central1-project-2.cloudfunctions.net/project-2-alpha-TestFunction: 401: Unauthorized
