gcp_adc

Injects a GCP OAuth2 access token into outbound requests.
On this page

Injects a GCP OAuth2 access token into outbound requests.

Configuration Notes

Experimental: requires the gcp-adc-filter cargo feature, which is off by default and activates the experimental marker. This filter is a work in progress and its configuration surface may change between releases.

Acquires a token via Application Default Credentials (GKE metadata server) and injects Authorization: Bearer <token> on every proxied request, keeping GCP credentials invisible to the downstream client. There is no background refresh thread: caching is cache-through, the same as [crate::azure::azure_ad] — see [praxis_ai_apis::token_cache::TokenCache] for the exact contract.

Service-account key file (source: key_file) token fetch is not implemented yet — it needs JWT signing, which this workspace does not currently depend on. Config parsing, file resolution, and validation for key_file all work; on_request fails closed with a clear “not implemented” reason instead of silently 503ing forever.

Credential-source resolution happens at construct time: GOOGLE_APPLICATION_CREDENTIALS is read once when the pipeline is built (reload the config to pick up changes), and a gcloud user credential file (authorized_user) is rejected as a configuration error rather than silently falling through the ADC chain.

This filter only injects Authorization. Pointing the request at the correct Vertex endpoint (cluster endpoints + tls.sni) is the operator’s responsibility.

Whenever no valid token can be produced — none cached and the inline fetch fails — the request is rejected with 503 rather than forwarded unauthenticated.

Metadata requests use a proxy-free, redirect-free client pinned to the complete validated DNS result set. Metadata mode intentionally permits the protocol-owned private endpoint; arbitrary private hosts remain invalid configuration.

Configuration

FieldTypeRequiredDescription
sourceadc | metadata | key_filenoCredential source. Defaults to adc.
scopestringnoOAuth2 scope requested with the access token.
service_accountstringnoMetadata service account email, or default (the default). Only used with the metadata and adc sources; rejected for key_file. Interpolated into the metadata path, so it must be default or a service-account email (letters, digits, @, ., -, _).
credentials_filestringnoPath to a service-account key JSON file. Required when source is key_file; rejected for the other sources (adc reads GOOGLE_APPLICATION_CREDENTIALS instead).
metadata_hoststringnoGCE/GKE metadata server host. Defaults to the real metadata server; the only other accepted value is a 127.0.0.1 loopback address, to point tests at a local mock. The metadata endpoint is only safe to reach over plain HTTP because it never leaves the VM/host, so nothing else is accepted (not even localhost, which is a resolvable hostname rather than a fixed address).

Example

filter: gcp_adc
source: adc
scope: https://www.googleapis.com/auth/cloud-platform