Fixed Google ADC functionality (#2282)

* Fixed Google ADC functionality

* Updated CHANGELOG.md

* Redo changes after merge-conflict

* Fixed docs

* Fixed linting issues

* Applied PR suggestions
This commit is contained in:
Koen van Zuijlen
2023-10-24 20:03:16 +01:00
committed by GitHub
parent 3862182039
commit 464f3bcf53
8 changed files with 175 additions and 161 deletions
+3
View File
@@ -500,6 +500,7 @@ type LegacyProvider struct {
GoogleAdminEmail string `flag:"google-admin-email" cfg:"google_admin_email"`
GoogleServiceAccountJSON string `flag:"google-service-account-json" cfg:"google_service_account_json"`
GoogleUseApplicationDefaultCredentials bool `flag:"google-use-application-default-credentials" cfg:"google_use_application_default_credentials"`
GoogleTargetPrincipal string `flag:"google-target-principal" cfg:"google_target_principal"`
// These options allow for other providers besides Google, with
// potential overrides.
@@ -600,6 +601,7 @@ func legacyGoogleFlagSet() *pflag.FlagSet {
flagSet.String("google-admin-email", "", "the google admin to impersonate for api calls")
flagSet.String("google-service-account-json", "", "the path to the service account json credentials")
flagSet.String("google-use-application-default-credentials", "", "use application default credentials instead of service account json (i.e. GKE Workload Identity)")
flagSet.String("google-target-principal", "", "the targetprincipal to impersonate when using ADC")
return flagSet
}
@@ -741,6 +743,7 @@ func (l *LegacyProvider) convert() (Providers, error) {
AdminEmail: l.GoogleAdminEmail,
ServiceAccountJSON: l.GoogleServiceAccountJSON,
UseApplicationDefaultCredentials: l.GoogleUseApplicationDefaultCredentials,
TargetPrincipal: l.GoogleTargetPrincipal,
}
}
+5 -3
View File
@@ -178,19 +178,21 @@ type GitHubOptions struct {
type GitLabOptions struct {
// Group sets restrict logins to members of this group
Group []string `json:"group,omitempty"`
// Projects restricts logins to members of any of these projects
// Projects restricts logins to members of these projects
Projects []string `json:"projects,omitempty"`
}
type GoogleOptions struct {
// Groups sets restrict logins to members of this google group
// Groups sets restrict logins to members of this Google group
Groups []string `json:"group,omitempty"`
// AdminEmail is the google admin to impersonate for api calls
// AdminEmail is the Google admin to impersonate for api calls
AdminEmail string `json:"adminEmail,omitempty"`
// ServiceAccountJSON is the path to the service account json credentials
ServiceAccountJSON string `json:"serviceAccountJson,omitempty"`
// UseApplicationDefaultCredentials is a boolean whether to use Application Default Credentials instead of a ServiceAccountJSON
UseApplicationDefaultCredentials bool `json:"useApplicationDefaultCredentials,omitempty"`
// TargetPrincipal is the Google Service Account used for Application Default Credentials
TargetPrincipal string `json:"targetPrincipal,omitempty"`
}
type OIDCOptions struct {