tag v0.155.0 Tagger: imagebuilder-bot <imagebuilder-bots+imagebuilder-bot@redhat.com> Changes with 0.155.0 ---------------- * Fedora 43: add shadow-utils when LockRoot is enabled, update cloud-init service name (osbuild/images#1618) * Author: Achilleas Koutsou, Reviewers: Gianluca Zuccarelli, Michael Vogt * Update osbuild dependency commit ID to latest (osbuild/images#1609) * Author: SchutzBot, Reviewers: Achilleas Koutsou, Simon de Vlieger, Tomáš Hozza * Update snapshots to 20250626 (osbuild/images#1623) * Author: SchutzBot, Reviewers: Achilleas Koutsou, Simon de Vlieger * distro/rhel9: xz compress azure-cvm image type [HMS-8587] (osbuild/images#1620) * Author: Achilleas Koutsou, Reviewers: Simon de Vlieger, Tomáš Hozza * distro/rhel: introduce new image type: Azure SAP Apps [HMS-8738] (osbuild/images#1612) * Author: Achilleas Koutsou, Reviewers: Simon de Vlieger, Tomáš Hozza * distro/rhel: move ansible-core to sap_extras_pkgset (osbuild/images#1624) * Author: Achilleas Koutsou, Reviewers: Brian C. Lane, Tomáš Hozza * github/create-tag: allow passing the version when run manually (osbuild/images#1621) * Author: Achilleas Koutsou, Reviewers: Lukáš Zapletal, Tomáš Hozza * rhel9: move image-config into pure YAML (HMS-8593) (osbuild/images#1616) * Author: Michael Vogt, Reviewers: Achilleas Koutsou, Simon de Vlieger * test: split manifest checksums into separate files (osbuild/images#1625) * Author: Achilleas Koutsou, Reviewers: Simon de Vlieger, Tomáš Hozza — Somewhere on the Internet, 2025-06-30 --- tag v0.156.0 Tagger: imagebuilder-bot <imagebuilder-bots+imagebuilder-bot@redhat.com> Changes with 0.156.0 ---------------- * Many: delete repositories for EOL distributions (HMS-7044) (osbuild/images#1607) * Author: Tomáš Hozza, Reviewers: Michael Vogt, Simon de Vlieger * RHSM/facts: add 'image-builder CLI' API type (osbuild/images#1640) * Author: Tomáš Hozza, Reviewers: Brian C. Lane, Simon de Vlieger * Update dependencies 2025-06-29 (osbuild/images#1628) * Author: SchutzBot, Reviewers: Simon de Vlieger, Tomáš Hozza * Update osbuild dependency commit ID to latest (osbuild/images#1627) * Author: SchutzBot, Reviewers: Simon de Vlieger, Tomáš Hozza * [RFC] image: drop `InstallWeakDeps` from image.DiskImage (osbuild/images#1642) * Author: Michael Vogt, Reviewers: Brian C. Lane, Simon de Vlieger, Tomáš Hozza * build(deps): bump the go-deps group across 1 directory with 3 updates (osbuild/images#1632) * Author: dependabot[bot], Reviewers: SchutzBot, Tomáš Hozza * distro/rhel10: xz compress azure-cvm image type (osbuild/images#1638) * Author: Achilleas Koutsou, Reviewers: Brian C. Lane, Simon de Vlieger * distro: cleanup/refactor distro/{defs,generic} (HMS-8744) (osbuild/images#1570) * Author: Michael Vogt, Reviewers: Simon de Vlieger, Tomáš Hozza * distro: remove some hardcoded values from generic/images.go (osbuild/images#1636) * Author: Michael Vogt, Reviewers: Simon de Vlieger, Tomáš Hozza * distro: small tweaks for the YAML based imagetypes (osbuild/images#1622) * Author: Michael Vogt, Reviewers: Brian C. Lane, Simon de Vlieger * fedora/wsl: packages and locale (osbuild/images#1635) * Author: Simon de Vlieger, Reviewers: Michael Vogt, Tomáš Hozza * image/many: make compression more generic (osbuild/images#1634) * Author: Simon de Vlieger, Reviewers: Brian C. Lane, Michael Vogt * manifest: handle content template name with spaces (osbuild/images#1641) * Author: Bryttanie, Reviewers: Brian C. Lane, Michael Vogt, Tomáš Hozza * many: implement gzip (osbuild/images#1633) * Author: Simon de Vlieger, Reviewers: Michael Vogt, Tomáš Hozza * rhel/azure: set GRUB_TERMINAL based on architecture [RHEL-91383] (osbuild/images#1626) * Author: Achilleas Koutsou, Reviewers: Simon de Vlieger, Tomáš Hozza — Somewhere on the Internet, 2025-07-07 ---
102 lines
3 KiB
Go
102 lines
3 KiB
Go
// Copyright 2023 Google LLC
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
package credentials
|
|
|
|
import (
|
|
"context"
|
|
"encoding/json"
|
|
"errors"
|
|
"fmt"
|
|
"net/url"
|
|
"strings"
|
|
"time"
|
|
|
|
"cloud.google.com/go/auth"
|
|
"cloud.google.com/go/compute/metadata"
|
|
)
|
|
|
|
var (
|
|
computeTokenMetadata = map[string]interface{}{
|
|
"auth.google.tokenSource": "compute-metadata",
|
|
"auth.google.serviceAccount": "default",
|
|
}
|
|
computeTokenURI = "instance/service-accounts/default/token"
|
|
)
|
|
|
|
// computeTokenProvider creates a [cloud.google.com/go/auth.TokenProvider] that
|
|
// uses the metadata service to retrieve tokens.
|
|
func computeTokenProvider(opts *DetectOptions, client *metadata.Client) auth.TokenProvider {
|
|
return auth.NewCachedTokenProvider(&computeProvider{
|
|
scopes: opts.Scopes,
|
|
client: client,
|
|
tokenBindingType: opts.TokenBindingType,
|
|
}, &auth.CachedTokenProviderOptions{
|
|
ExpireEarly: opts.EarlyTokenRefresh,
|
|
DisableAsyncRefresh: opts.DisableAsyncRefresh,
|
|
})
|
|
}
|
|
|
|
// computeProvider fetches tokens from the google cloud metadata service.
|
|
type computeProvider struct {
|
|
scopes []string
|
|
client *metadata.Client
|
|
tokenBindingType TokenBindingType
|
|
}
|
|
|
|
type metadataTokenResp struct {
|
|
AccessToken string `json:"access_token"`
|
|
ExpiresInSec int `json:"expires_in"`
|
|
TokenType string `json:"token_type"`
|
|
}
|
|
|
|
func (cs *computeProvider) Token(ctx context.Context) (*auth.Token, error) {
|
|
tokenURI, err := url.Parse(computeTokenURI)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
hasScopes := len(cs.scopes) > 0
|
|
if hasScopes || cs.tokenBindingType != NoBinding {
|
|
v := url.Values{}
|
|
if hasScopes {
|
|
v.Set("scopes", strings.Join(cs.scopes, ","))
|
|
}
|
|
switch cs.tokenBindingType {
|
|
case MTLSHardBinding:
|
|
v.Set("transport", "mtls")
|
|
v.Set("binding-enforcement", "on")
|
|
case ALTSHardBinding:
|
|
v.Set("transport", "alts")
|
|
}
|
|
tokenURI.RawQuery = v.Encode()
|
|
}
|
|
tokenJSON, err := cs.client.GetWithContext(ctx, tokenURI.String())
|
|
if err != nil {
|
|
return nil, fmt.Errorf("credentials: cannot fetch token: %w", err)
|
|
}
|
|
var res metadataTokenResp
|
|
if err := json.NewDecoder(strings.NewReader(tokenJSON)).Decode(&res); err != nil {
|
|
return nil, fmt.Errorf("credentials: invalid token JSON from metadata: %w", err)
|
|
}
|
|
if res.ExpiresInSec == 0 || res.AccessToken == "" {
|
|
return nil, errors.New("credentials: incomplete token received from metadata")
|
|
}
|
|
return &auth.Token{
|
|
Value: res.AccessToken,
|
|
Type: res.TokenType,
|
|
Expiry: time.Now().Add(time.Duration(res.ExpiresInSec) * time.Second),
|
|
Metadata: computeTokenMetadata,
|
|
}, nil
|
|
|
|
}
|