Inspect Google Application Default Credentials Tokens
Simple script which prints out the principal/user currently enabled for Application Default Credentials
If you want a standalone script without importing the library, see the example/manual.py script in this repo
stsinspect.py
from gcp_adc_util.inspect import ADCInspect
p = ADCInspect()
print(p.getProjectID())
print(p.getPrincipal())
requires
Python3.11+
User
gcloud auth application-default login
$ python3 stsinspect.py
admin@domain.com
With ServiceAccount JSON
$ export GOOGLE_APPLICATION_CREDENTIALS=/path/to/svc-account.json
$ python stsinspect.py
svc-account@PROJECT.iam.gserviceaccount.com
With GCE Metadata Server
python3 stsinspect.py
708288290784-compute@developer.gserviceaccount.com
With GCE Metadata Server Emulator
https://github.com/salrashid123/gce_metadata_server
export GCE_METADATA_HOST=localhost:8080
python3 stsinspect.py
Workload Federation OIDC using curl
export BASIC_AUTH_HEADER="MzI1NTU5NDA1NTkuYXBwcy5nb29nbGV1c2VyY29udGVudC5jb206Wm1zc0xOakp5Mjk5OGhENENUZzJlanIy"
STS_TOKEN_INSPECT=$(curl -s https://sts.googleapis.com/v1/token -H "Authorization: Basic $BASIC_AUTH_HEADER" \
--data-urlencode "audience=//iam.googleapis.com/projects/$PROJECT_NUMBER/locations/global/workloadIdentityPools/$POOL_ID/providers/$PROVIDER_ID" \
--data-urlencode "grant_type=urn:ietf:params:oauth:grant-type:token-exchange" \
--data-urlencode "requested_token_type=urn:ietf:params:oauth:token-type:access_token" \
--data-urlencode "scope=https://www.googleapis.com/auth/cloud-platform" \
--data-urlencode "subject_token_type=urn:ietf:params:oauth:token-type:jwt" \
--data-urlencode "subject_token=$SUBJECT_TOKEN" | jq -r .access_token)
echo $STS_TOKEN_INSPECT
curl -s -H "Authorization: Basic $BASIC_AUTH_HEADER" -H "Content-Type: application/json" --data "{\"token\":\"$STS_TOKEN_INSPECT\"}" https://sts.googleapis.com/v1/introspect
Workload federation OIDC
see Simple GCP OIDC workload Federation using a fake oidc server
$ cat sts-creds.json
{
"universe_domain": "googleapis.com",
"type": "external_account",
"audience": "//iam.googleapis.com/projects/995081019036/locations/global/workloadIdentityPools/fake-oidc-pool-1/providers/fake-oidc-provider-1",
"subject_token_type": "urn:ietf:params:oauth:token-type:jwt",
"token_url": "https://sts.googleapis.com/v1/token",
"credential_source": {
"file": "/tmp/oidccred.txt",
"format": {
"type": "text"
}
},
"token_info_url": "https://sts.googleapis.com/v1/introspect"
}
$ export GOOGLE_APPLICATION_CREDENTIALS=`pwd`/sts-creds.json
$ python3 stsinspect.py
principal://iam.googleapis.com/projects/995081019036/locations/global/workloadIdentityPools/fake-oidc-pool-1/subject/alice@domain.com
Workload Federation mTLS
$ cat sts-creds-mtls.json
{
"universe_domain": "googleapis.com",
"type": "external_account",
"audience": "//iam.googleapis.com/projects/995081019036/locations/global/workloadIdentityPools/cert-pool-1/providers/cert-provider-1",
"subject_token_type": "urn:ietf:params:oauth:token-type:mtls",
"token_url": "https://sts.mtls.googleapis.com/v1/token",
"credential_source": {
"certificate": {
"certificate_config_location": "/pat/to/cert_config.json"
}
},
"token_info_url": "https://sts.mtls.googleapis.com/v1/introspect"
}
$ export GOOGLE_APPLICATION_CREDENTIALS=`pwd`/sts-creds-mtls.json
$ python3 stsinspect.py
principal://iam.googleapis.com/projects/995081019036/locations/global/workloadIdentityPools/cert-pool-1/subject/workload3
Workload Federation with service_account_impersonation_url
$ cat sts-creds-mtls-impersonation.json
{
"universe_domain": "googleapis.com",
"type": "external_account",
"audience": "//iam.googleapis.com/projects/995081019036/locations/global/workloadIdentityPools/cert-pool-1/providers/cert-provider-1",
"subject_token_type": "urn:ietf:params:oauth:token-type:mtls",
"token_url": "https://sts.mtls.googleapis.com/v1/token",
"credential_source": {
"certificate": {
"certificate_config_location": "/path/to/cert_config.json"
}
},
"service_account_impersonation_url": "https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/wif-svc@core-eso.iam.gserviceaccount.com:generateAccessToken",
"token_info_url": "https://sts.mtls.googleapis.com/v1/introspect"
}
$ export GOOGLE_APPLICATION_CREDENTIALS=`pwd`/sts-creds-mtls-impersonation.json
$ python3 stsinspect.py
wif-svc@core-eso.iam.gserviceaccount.com
Workforce Federation SAML
$ cat saml-creds.json
{
"universe_domain": "googleapis.com",
"type": "external_account",
"audience": "//iam.googleapis.com/locations/global/workforcePools/wfpool-saml/providers/wfprovider-saml",
"subject_token_type": "urn:ietf:params:oauth:token-type:saml2",
"token_url": "https://sts.googleapis.com/v1/token",
"credential_source": {
"file": "/tmp/samlassertion.txt",
"format": {
"type": "text"
}
},
"workforce_pool_user_project": "core-eso",
"token_info_url": "https://sts.googleapis.com/v1/introspect"
}
$ export GOOGLE_APPLICATION_CREDENTIALS=`pwd`/saml-creds.json
$ python3 stsinspect.py
principal://iam.googleapis.com/locations/global/workforcePools/wfpool-saml/subject/alice@domain.com
Workload Federation with AWS
see GCP Workload Identity Federation using AWS Credentials
$ cat sts-creds-aws.json
{
"universe_domain": "googleapis.com",
"type": "external_account",
"audience": "//iam.googleapis.com/projects/995081019036/locations/global/workloadIdentityPools/aws-pool-1/providers/aws-provider-1",
"subject_token_type": "urn:ietf:params:aws:token-type:aws4_request",
"token_url": "https://sts.googleapis.com/v1/token",
"credential_source": {
"environment_id": "aws1",
"region_url": "http://169.254.169.254/latest/meta-data/placement/availability-zone",
"url": "http://169.254.169.254/latest/meta-data/iam/security-credentials",
"regional_cred_verification_url": "https://sts.{region}.amazonaws.com?Action=GetCallerIdentity&Version=2011-06-15"
},
"token_info_url": "https://sts.googleapis.com/v1/introspect"
}
export AWS_ACCESS_KEY_ID=AKIAUH-redacted
export AWS_SECRET_ACCESS_KEY=lIs-redacted
export AWS_DEFAULT_REGION=us-east-2
$ aws sts get-caller-identity
{
"UserId": "AIDAUH-redacted",
"Account": "291738886548",
"Arn": "arn:aws:iam::291738886548:user/svcacct1"
}
$ export GOOGLE_APPLICATION_CREDENTIALS=`pwd`/sts-creds-aws.json
$ python3 stsinspect.py
principal://iam.googleapis.com/projects/995081019036/locations/global/workloadIdentityPools/aws-pool-1/subject/arn:aws:iam::291738886548:user/svcacct1
Workload Federation with Azure
see Exchange Google and Firebase OIDC tokens for Azure STS
TODO: incorporate into gcloud alias for Application Default Credentials
Metadata
Release files for gcp-adc-util 0.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| gcp_adc_util-0.0.1.tar.gz | 8.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| gcp_adc_util-0.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.3 kB
Release files / gcp_adc_util-0.0.1.tar.gz
| Download URL | gcp_adc_util-0.0.1.tar.gz |
|---|---|
| Size | 8.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
61efcd9e59081a0314f0ce81858f08f551d60dd3a45829d22076d758cc93b6f8
|
|
BLAKE2b-256 checksum How to use checksums |
4677dd5daec257d8fe6e0b4407ddeb6d9b8371b4722a0227632b3a475af586dd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/5.1.1 CPython/3.12.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Nov 27, 2024.
Transparency logRelease files / gcp_adc_util-0.0.1-py3-none-any.whl
| Download URL | gcp_adc_util-0.0.1-py3-none-any.whl |
|---|---|
| Size | 9.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ba67128922fd962eac7a210c430cd2d6ed82fecbf6f81b82ec0a41af42c7d1df
|
|
BLAKE2b-256 checksum How to use checksums |
b4aba9112787d24c6e9850d14f79b5c829ae30eea6aa08b15239727fd62e70e1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/5.1.1 CPython/3.12.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Nov 27, 2024.
Transparency log