feat(python-client): Add Google Cloud authentication support#6
Merged
steren merged 1 commit intoGoogleCloudPlatform:mainfrom Jan 12, 2026
Merged
Conversation
Collaborator
|
Thanks! lmk when I should review |
88548c6 to
0e521a7
Compare
Collaborator
Author
|
@steren PTAL |
- Adds 'use_google_auth' parameter to Sandbox.create and Sandbox.attach for automatic OIDC token fetching. - Integrates google-auth with robust fallback (ADC -> Metadata). - Simplifies audience derivation to always use 'https://' for OIDC compatibility. - Implements automatic token refresh during reconnection to handle 1-hour OIDC expiration. - Centralizes error handling with '_append_error_hint' to provide actionable 401/403 hints and Cloud Run troubleshooting links. - Updates all examples and tests to match the new signature and logic. - Updates .gitignore to ignore venv/ and build/.
0e521a7 to
ad77d23
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR introduces built-in authentication support for the Python client, enabling secure connections to Cloud Run services protected by IAM.
Key Changes
Public API Update
use_google_auth(bool) parameter toSandbox.createandSandbox.attach. When enabled, the client automatically fetches an OIDC ID token.Authentication Logic
_get_id_tokento fetch OIDC tokens automatically.DefaultCredentialsErroris raised.https://).use_google_authis enabled.Testing & Examples
test_sandbox.pyverifying the auth flow, mock credential handling, token refreshing, and error hint generation.basic.py,checkpoint.py, etc.) to enableuse_google_auth=Trueby default.