Google Cloud Java SDK dengan Workload Identity?
Mencoba mencari tahu cara mengautentikasi dengan API penyimpanan dari dalam cluster GKE.
Kode:
Storage storage = StorageOptions.newBuilder()
.setCredentials(ServiceAccountCredentials.getApplicationDefault())
.setProjectId(gcpProjectId)
.build().getService();
getApplicationDefault() didokumentasikan untuk menggunakan cara ini untuk mengautentikasi dengan API:
- File kredensial yang ditunjukkan oleh variabel lingkungan {@code GOOGLE_APPLICATION_CREDENTIALS}
- Kredensial diberikan oleh perintah {@code gcloud auth application-default login} Google Cloud SDK
- Kredensial bawaan Google App Engine
- Kredensial bawaan Google Cloud Shell
- Kredensial bawaan Google Compute Engine
Aplikasi menggunakan fitur identitas beban kerja GCP, sehingga akun layanan aplikasi (dalam cluster) dianotasi dengan:
serviceAccount.annotations.iam.gke.io/gcp-service-account: [email protected]
Sekarang panggilan ke akun penyimpanan gagal dengan kesalahan berikut:
{
"code" : 403,
"errors" : [ {
"domain" : "global",
"message" : "Primary: /namespaces/my-project.svc.id.goog with additional claims does not have storage.objects.create access to the Google Cloud Storage object.",
"reason" : "forbidden"
} ],
"message" : "Primary: /namespaces/my-project.svc.id.goog with additional claims does not have storage.objects.create access to the Google Cloud Storage object."
}
Ini membuat saya berpikir bahwa identitas beban kerja tidak berfungsi dengan benar. Saya mengharapkan untuk menerima pesan kesalahan untuk akun layanan saya beranotasi dan bukan yang default.
Apakah ada hal lain yang seharusnya saya lakukan?
Jawaban
Anotasinya salah. Dari pada:
serviceAccount.annotations.iam.gke.io/gcp-service-account: [email protected]
itu pasti
iam.gke.io/gcp-service-account: [email protected]
Sekarang pesan kesalahan juga menunjukkan bahwa aplikasi menggunakan identitas beban kerja:
java.io.IOException: Unexpected Error code 403 trying to get security access token from Compute Engine metadata for the default service account: Unable to generate access token; IAM returned 403 Forbidden: The caller does not have permission
This error could be caused by a missing IAM policy binding on the target IAM service account.
For more information, refer to the Workload Identity documentation:
https://cloud.google.com/kubernetes-engine/docs/how-to/workload-identity#creating_a_relationship_between_ksas_and_gsas