Repository navigation
docs(auth): link ComputeEngineCredentials Javadoc to bound token section - #14627
Open
macastelaz wants to merge 6 commits into
Open
macastelaz wants to merge 6 commits into
macastelaz wants to merge 6 commits into
Conversation
Adds a README section and ComputeEngineCredentials class Javadoc covering: - bound tokens are the default when an agent identity workload certificate is present, and require mTLS with the same certificate - when a bound token is requested (cert discovery, agent SPIFFE trust domain) - opt-out env vars and precedence: GOOGLE_API_ENABLE_RUNTIME_BOUND_TOKEN over the legacy GOOGLE_API_PREVENT_AGENT_TOKEN_SHARING_FOR_GCP_SERVICES, and GOOGLE_API_USE_CLIENT_CERTIFICATE=false also disabling binding - the process-wide scope of the opt-out - requesting unbound ID tokens for specific targets with IdTokenProvider.Option.BIND_ID_TOKEN_FALSE - the ADK for Java known limitation and its workaround
Contributor
There was a problem hiding this comment.
Code Review
This pull request updates the Javadoc for the ComputeEngineCredentials class to document that certificate-bound access tokens and ID tokens are requested by default when a workload certificate for an agent identity is available. It also adds references to IdTokenProvider.Option.DISABLE_BOUND_ID_TOKEN and the Google Auth Library guide. I have no feedback to provide.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Important
Merge after
cl/996749889publishes on DevSite (or retarget tomainifagentic-identities-bound-tokenmerges first).Summary
Follow-up to #14557 (comment): updates the
ComputeEngineCredentialsclass Javadoc link to point directly to the new#certificate-bound-tokens-for-agent-identitiessection anchor introduced incl/996749889: