Skip to content

fix(auth): fall back to metadata service when CLOUDSDK_CONFIG points at a directory without the well-known ADC file - #1094

Open
Vasu Madaan (Vasu-Madaan) wants to merge 1 commit into
talkiq:masterfrom
Vasu-Madaan:fix/well-known-adc-cloudsdk-config-fallback
Open

Vasu Madaan (Vasu-Madaan) wants to merge 1 commit into
talkiq:masterfrom
Vasu-Madaan:fix/well-known-adc-cloudsdk-config-fallback

Conversation

@Vasu-Madaan

Copy link
Copy Markdown

Fixes #936.

Problem

When CLOUDSDK_CONFIG is set in the environment (a common workaround for readOnlyRootFilesystem containers that need a writable gcloud CLI config directory), and the file at $CLOUDSDK_CONFIG/application_default_credentials.json does not exist, get_service_data() raises FileNotFoundError instead of returning {}. That prevents Token from falling back to the GCE metadata service, which breaks Workload Identity–only authentication for any async workload whose base image happens to export CLOUDSDK_CONFIG.

The docstring on get_service_data() states the function is meant to match google.auth.default(). In google-auth, _get_gcloud_sdk_credentials() guards the well-known file with os.path.isfile() and silently returns None when it is missing, regardless of CLOUDSDK_CONFIG. Only GOOGLE_APPLICATION_CREDENTIALS is treated as explicit user intent.

Fix

In the well-known-file branch, set_explicitly is now always False (previously bool(cloudsdk_config)). The GOOGLE_APPLICATION_CREDENTIALS branch is unchanged; a missing file at that path still raises.

Testing

  • Reproduced the failure end-to-end with a deferrable GCSObjects* sensor on a Kubernetes environment where the triggerer pod exported CLOUDSDK_CONFIG=/tmp/gcloud with no file at that path — trigger yielded FileNotFoundError instead of falling back to WI. With this patch applied the trigger polls cleanly through the metadata service and the sensor completes normally.
  • Two new unit tests in auth/tests/unit/token_test.py. All existing and new tests pass locally.

…to a directory without the well-known ADC file

CLOUDSDK_CONFIG only relocates the gcloud CLI config directory (commonly
set to work around readOnlyRootFilesystem containers); it is not an ADC
directive. Prior to this change, its mere presence in the environment
flipped set_explicitly=True, so a missing $CLOUDSDK_CONFIG/
application_default_credentials.json raised FileNotFoundError instead of
falling through to the GCE metadata service.

The docstring on get_service_data() states the function is meant to
match google.auth.default(). Its _get_gcloud_sdk_credentials() step
silently returns None when the well-known file is absent, regardless of
CLOUDSDK_CONFIG, so ADC proceeds to the metadata service. This change
brings the async library in line with that reference behaviour.

Only GOOGLE_APPLICATION_CREDENTIALS remains an explicit user directive:
if it is set, a missing file still raises (the else-branch is unchanged,
and a regression test covers this).

Fixes talkiq#936.
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Workspace UI

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 3bc92486-0d83-4175-9493-c920da9e85e9

📥 Commits

Reviewing files that changed from the base of the PR and between 764f76f and c9a565e.

📒 Files selected for processing (2)
  • auth/gcloud/aio/auth/token.py
  • auth/tests/unit/token_test.py

Updates ADC discovery so missing well-known credentials under CLOUDSDK_CONFIG falls back to GCE metadata, while missing explicitly configured GOOGLE_APPLICATION_CREDENTIALS still raises. Adds tests for both behaviors.

Overall Judgement: ✅ Ready to merge — behavior is narrowly scoped and covered by targeted unit tests.

Walkthrough

get_service_data now allows metadata fallback when SDK-derived credentials are absent while continuing to raise errors for explicitly configured missing credentials.

Changes

Credential discovery behavior

Layer / File(s) Summary
Credential fallback and regression coverage
auth/gcloud/aio/auth/token.py, auth/tests/unit/token_test.py
CLOUDSDK_CONFIG-derived paths are no longer treated as explicit user credentials, while missing GOOGLE_APPLICATION_CREDENTIALS paths still raise FileNotFoundError; tests cover both cases.

Assessment against linked issues

Objective Addressed Explanation
Allow metadata-server credential discovery when CLOUDSDK_CONFIG exists without the well-known ADC file [#936] ✅
Preserve errors for explicitly configured missing credential files [#936] ✅
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

FileNotFoundError Not Being Caught In get_service_data() (token.py)

1 participant