diff --git a/spring-vault-core/pom.xml b/spring-vault-core/pom.xml index f5d52e53..876c65df 100644 --- a/spring-vault-core/pom.xml +++ b/spring-vault-core/pom.xml @@ -197,6 +197,7 @@ com.google.cloud google-cloud-iamcredentials + true com.fasterxml.jackson.core @@ -211,7 +212,6 @@ commons-logging - true diff --git a/spring-vault-core/src/main/java/org/springframework/vault/authentication/DefaultGcpCredentialsAccessors.java b/spring-vault-core/src/main/java/org/springframework/vault/authentication/DefaultGoogleCredentialsAccessors.java similarity index 89% rename from spring-vault-core/src/main/java/org/springframework/vault/authentication/DefaultGcpCredentialsAccessors.java rename to spring-vault-core/src/main/java/org/springframework/vault/authentication/DefaultGoogleCredentialsAccessors.java index 83af9794..6369a6d8 100644 --- a/spring-vault-core/src/main/java/org/springframework/vault/authentication/DefaultGcpCredentialsAccessors.java +++ b/spring-vault-core/src/main/java/org/springframework/vault/authentication/DefaultGoogleCredentialsAccessors.java @@ -21,14 +21,14 @@ import com.google.auth.oauth2.GoogleCredentials; import com.google.auth.oauth2.ServiceAccountCredentials; /** - * Default implementation of {@link GcpCredentialsAccountIdAccessor}. Used by + * Default implementation of {@link GoogleCredentialsAccountIdAccessor}. Used by * {@link GcpIamCredentialsAuthentication}. * * @author Andreas Gebauer - * @since 2.4 + * @since 2.3.2 * @see GcpIamCredentialsAuthentication */ -enum DefaultGcpCredentialsAccessors implements GcpCredentialsAccountIdAccessor { +enum DefaultGoogleCredentialsAccessors implements GoogleCredentialsAccountIdAccessor { INSTANCE; diff --git a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthentication.java b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthentication.java index 307718a1..fd1e0d2e 100644 --- a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthentication.java +++ b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthentication.java @@ -41,7 +41,8 @@ import org.springframework.web.client.RestOperations; /** * GCP IAM login implementation using GCP IAM service accounts to legitimate its - * authenticity via JSON Web Token. + * authenticity via JSON Web Token using the deprecated IAM + * {@code projects.serviceAccounts.signJwt} method. *

* This authentication method uses Googles IAM API to obtain a signed token for a specific * {@link com.google.api.client.auth.oauth2.Credential}. Project and service account @@ -64,7 +65,7 @@ import org.springframework.web.client.RestOperations; * @see GCP: * projects.serviceAccounts.signJwt - * @deprecated Use {@link GcpIamCredentialsAuthentication} instead. + * @deprecated since 2.3.2, use {@link GcpIamCredentialsAuthentication} instead. */ @Deprecated public class GcpIamAuthentication extends GcpJwtAuthenticationSupport implements ClientAuthentication { diff --git a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthenticationOptions.java b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthenticationOptions.java index 56428d64..be39a2f1 100644 --- a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthenticationOptions.java +++ b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthenticationOptions.java @@ -36,35 +36,15 @@ import org.springframework.util.Assert; * @see GcpIamAuthentication * @see #builder() * @since 2.1 + * @deprecated since 2.3.2 */ -public class GcpIamAuthenticationOptions { +@Deprecated +public class GcpIamAuthenticationOptions extends GcpIamAuthenticationSupport { public static final String DEFAULT_GCP_AUTHENTICATION_PATH = "gcp"; - /** - * Path of the gcp authentication backend mount. - */ - private final String path; - private final GcpCredentialSupplier credentialSupplier; - /** - * Name of the role against which the login is being attempted. If role is not - * specified, the friendly name (i.e., role name or username) of the IAM principal - * authenticated. If a matching role is not found, login fails. - */ - private final String role; - - /** - * JWT validity/expiration. - */ - private final Duration jwtValidity; - - /** - * {@link Clock} to calculate JWT expiration. - */ - private final Clock clock; - /** * Provide the service account id to use as sub/iss claims. */ @@ -79,11 +59,9 @@ public class GcpIamAuthenticationOptions { Duration jwtValidity, Clock clock, GcpServiceAccountIdAccessor serviceAccountIdSupplier, GcpProjectIdAccessor projectIdAccessor) { - this.path = path; + super(path, role, jwtValidity, clock); + this.credentialSupplier = credentialSupplier; - this.role = role; - this.jwtValidity = jwtValidity; - this.clock = clock; this.serviceAccountIdAccessor = serviceAccountIdSupplier; this.projectIdAccessor = projectIdAccessor; } @@ -95,13 +73,6 @@ public class GcpIamAuthenticationOptions { return new GcpIamAuthenticationOptionsBuilder(); } - /** - * @return the path of the gcp authentication backend mount. - */ - public String getPath() { - return this.path; - } - /** * @return the gcp {@link Credential} supplier. */ @@ -109,27 +80,6 @@ public class GcpIamAuthenticationOptions { return this.credentialSupplier; } - /** - * @return name of the role against which the login is being attempted. - */ - public String getRole() { - return this.role; - } - - /** - * @return {@link Duration} of the JWT to generate. - */ - public Duration getJwtValidity() { - return this.jwtValidity; - } - - /** - * @return {@link Clock} used to calculate epoch seconds until the JWT expires. - */ - public Clock getClock() { - return this.clock; - } - /** * @return the service account id to use as sub/iss claims. * @since 2.1 diff --git a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthenticationSupport.java b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthenticationSupport.java new file mode 100644 index 00000000..6be477a4 --- /dev/null +++ b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamAuthenticationSupport.java @@ -0,0 +1,91 @@ +/* + * Copyright 2018-2021 the original author or authors. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * https://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.springframework.vault.authentication; + +import java.time.Clock; +import java.time.Duration; + +/** + * Support class for Google Cloud IAM-based Authentication options. + *

+ * Mainly to support implementations within the framework. + * + * @author Mark Paluch + * @since 2.3.2 + * @see GcpIamAuthenticationOptions + * @see GcpIamCredentialsAuthenticationOptions + */ +public abstract class GcpIamAuthenticationSupport { + + /** + * Path of the gcp authentication backend mount. + */ + private final String path; + + /** + * Name of the role against which the login is being attempted. If role is not + * specified, the friendly name (i.e., role name or username) of the IAM principal + * authenticated. If a matching role is not found, login fails. + */ + private final String role; + + /** + * JWT validity/expiration. + */ + private final Duration jwtValidity; + + /** + * {@link Clock} to calculate JWT expiration. + */ + private final Clock clock; + + protected GcpIamAuthenticationSupport(String path, String role, Duration jwtValidity, Clock clock) { + + this.path = path; + this.role = role; + this.jwtValidity = jwtValidity; + this.clock = clock; + } + + /** + * @return the path of the gcp authentication backend mount. + */ + public String getPath() { + return this.path; + } + + /** + * @return name of the role against which the login is being attempted. + */ + public String getRole() { + return this.role; + } + + /** + * @return {@link Duration} of the JWT to generate. + */ + public Duration getJwtValidity() { + return this.jwtValidity; + } + + /** + * @return {@link Clock} used to calculate epoch seconds until the JWT expires. + */ + public Clock getClock() { + return this.clock; + } + +} diff --git a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamCredentialsAuthentication.java b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamCredentialsAuthentication.java index 5dd19635..c5df6918 100644 --- a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamCredentialsAuthentication.java +++ b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamCredentialsAuthentication.java @@ -39,8 +39,9 @@ import com.google.cloud.iam.credentials.v1.SignJwtResponse; import com.google.cloud.iam.credentials.v1.stub.IamCredentialsStubSettings; /** - * GCP IAM credentials login implementation using GCP IAM service accounts to legitimate - * its authenticity via JSON Web Token. + * Google Cloud IAM credentials login implementation using GCP IAM service accounts to + * legitimate its authenticity via JSON Web Token using the IAM Credentials + * {@code projects.serviceAccounts.signJwt} method. *

* This authentication method uses Googles IAM Credentials API to obtain a signed token * for a specific {@link com.google.api.client.auth.oauth2.Credential}. Service account @@ -50,7 +51,8 @@ import com.google.cloud.iam.credentials.v1.stub.IamCredentialsStubSettings; * {@link GcpIamCredentialsAuthentication} uses Google Java API that uses synchronous API. * * @author Andreas Gebauer - * @since 2.4 + * @author Mark Paluch + * @since 2.3.2 * @see GcpIamCredentialsAuthenticationOptions * @see HttpTransport * @see GoogleCredentials diff --git a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamCredentialsAuthenticationOptions.java b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamCredentialsAuthenticationOptions.java index 01bd3948..970a162d 100644 --- a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamCredentialsAuthenticationOptions.java +++ b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpIamCredentialsAuthenticationOptions.java @@ -21,110 +21,70 @@ import java.time.Duration; import org.springframework.lang.Nullable; import org.springframework.util.Assert; -import com.google.api.client.auth.oauth2.Credential; -import com.google.api.core.ApiClock; import com.google.auth.oauth2.GoogleCredentials; import com.google.auth.oauth2.ServiceAccountCredentials; -public class GcpIamCredentialsAuthenticationOptions { +/** + * Authentication options for {@link GcpIamCredentialsAuthentication}. + *

+ * Authentication options provide the path, a {@link GoogleCredentialsSupplier}, role and + * JWT expiry for GCP IAM authentication. Instances of this class are immutable once + * constructed. + * + * @author Andreas Gebauer + * @author Magnus Jungsbluth + * @see GcpIamCredentialsAuthentication + * @see #builder() + * @since 2.3.2 + */ +public class GcpIamCredentialsAuthenticationOptions extends GcpIamAuthenticationSupport { public static final String DEFAULT_GCP_AUTHENTICATION_PATH = "gcp"; /** - * Path of the gcp authentication backend mount. + * Provide the {@link GoogleCredentials}. */ - private final String path; - - private final GcpCredentialsSupplier credentialSupplier; - - /** - * Name of the role against which the login is being attempted. If role is not - * specified, the friendly name (i.e., role name or username) of the IAM principal - * authenticated. If a matching role is not found, login fails. - */ - private final String role; - - /** - * JWT validity/expiration. - */ - private final Duration jwtValidity; - - /** - * {@link ApiClock} to calculate JWT expiration. - */ - private final Clock clock; + private final GoogleCredentialsSupplier credentialSupplier; /** * Provide the service account id to use as sub/iss claims. */ - private final GcpCredentialsAccountIdAccessor serviceAccountIdAccessor; + private final GoogleCredentialsAccountIdAccessor serviceAccountIdAccessor; - private GcpIamCredentialsAuthenticationOptions(String path, GcpCredentialsSupplier credentialSupplier, String role, - Duration jwtValidity, Clock clock, GcpCredentialsAccountIdAccessor serviceAccountIdSupplier) { + private GcpIamCredentialsAuthenticationOptions(String path, GoogleCredentialsSupplier credentialSupplier, + String role, Duration jwtValidity, Clock clock, + GoogleCredentialsAccountIdAccessor serviceAccountIdAccessor) { - this.path = path; + super(path, role, jwtValidity, clock); this.credentialSupplier = credentialSupplier; - this.role = role; - this.jwtValidity = jwtValidity; - this.clock = clock; - this.serviceAccountIdAccessor = serviceAccountIdSupplier; + this.serviceAccountIdAccessor = serviceAccountIdAccessor; } /** - * @return a new - * {@link GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder}. + * @return a new {@link GoogleCloudIamAuthenticationOptionsBuilder}. */ - public static GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder builder() { - return new GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder(); + public static GoogleCloudIamAuthenticationOptionsBuilder builder() { + return new GoogleCloudIamAuthenticationOptionsBuilder(); } /** - * @return the path of the gcp authentication backend mount. + * @return the {@link GoogleCredentials} supplier. */ - public String getPath() { - return this.path; - } - - /** - * @return the gcp {@link Credential} supplier. - */ - public GcpCredentialsSupplier getCredentialSupplier() { + public GoogleCredentialsSupplier getCredentialSupplier() { return this.credentialSupplier; } - /** - * @return name of the role against which the login is being attempted. - */ - public String getRole() { - return this.role; - } - - /** - * @return {@link Duration} of the JWT to generate. - */ - public Duration getJwtValidity() { - return this.jwtValidity; - } - - /** - * @return {@link Clock} used to calculate epoch seconds until the JWT expires. - */ - public Clock getClock() { - return this.clock; - } - /** * @return the service account id to use as sub/iss claims. - * @since 2.1 */ - public GcpCredentialsAccountIdAccessor getServiceAccountIdAccessor() { + public GoogleCredentialsAccountIdAccessor getServiceAccountIdAccessor() { return this.serviceAccountIdAccessor; } /** * Builder for {@link GcpIamCredentialsAuthenticationOptions}. */ - public static class GcpIamCredentialsAuthenticationOptionsBuilder { + public static class GoogleCloudIamAuthenticationOptionsBuilder { private String path = DEFAULT_GCP_AUTHENTICATION_PATH; @@ -132,24 +92,23 @@ public class GcpIamCredentialsAuthenticationOptions { private String role; @Nullable - private GcpCredentialsSupplier credentialsSupplier; + private GoogleCredentialsSupplier credentialsSupplier; private Duration jwtValidity = Duration.ofMinutes(15); private Clock clock = Clock.systemDefaultZone(); - private GcpCredentialsAccountIdAccessor serviceAccountIdAccessor = DefaultGcpCredentialsAccessors.INSTANCE; + private GoogleCredentialsAccountIdAccessor serviceAccountIdAccessor = DefaultGoogleCredentialsAccessors.INSTANCE; - GcpIamCredentialsAuthenticationOptionsBuilder() { + GoogleCloudIamAuthenticationOptionsBuilder() { } /** * Configure the mount path, defaults to {@literal aws}. * @param path must not be empty or {@literal null}. - * @return {@code this} - * {@link GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder}. + * @return {@code this} {@link GoogleCloudIamAuthenticationOptionsBuilder}. */ - public GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder path(String path) { + public GoogleCloudIamAuthenticationOptionsBuilder path(String path) { Assert.hasText(path, "Path must not be empty"); @@ -160,14 +119,12 @@ public class GcpIamCredentialsAuthenticationOptions { /** * Configure static Google credentials, required to create a signed JWT. Either * use static credentials or provide a - * {@link #credentialsSupplier(GcpCredentialsSupplier) credentials provider}. + * {@link #credentialsSupplier(GoogleCredentialsSupplier) credentials provider}. * @param credentials must not be {@literal null}. - * @return {@code this} - * {@link GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder}. - * @see #credentialsSupplier(GcpCredentialsSupplier) + * @return {@code this} {@link GoogleCloudIamAuthenticationOptionsBuilder}. + * @see #credentialsSupplier(GoogleCredentialsSupplier) */ - public GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder credentials( - GoogleCredentials credentials) { + public GoogleCloudIamAuthenticationOptionsBuilder credentials(GoogleCredentials credentials) { Assert.notNull(credentials, "ServiceAccountCredentials must not be null"); @@ -175,16 +132,15 @@ public class GcpIamCredentialsAuthenticationOptions { } /** - * Configure a {@link GcpCredentialsSupplier}, required to create a signed JWT. + * Configure a {@link GoogleCredentialsSupplier}, required to create a signed JWT. * Alternatively, configure static {@link #credentials(GoogleCredentials) * credentials}. * @param credentialsSupplier must not be {@literal null}. - * @return {@code this} - * {@link GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder}. + * @return {@code this} {@link GoogleCloudIamAuthenticationOptionsBuilder}. * @see #credentials(GoogleCredentials) */ - public GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder credentialsSupplier( - GcpCredentialsSupplier credentialsSupplier) { + public GoogleCloudIamAuthenticationOptionsBuilder credentialsSupplier( + GoogleCredentialsSupplier credentialsSupplier) { Assert.notNull(credentialsSupplier, "GcpServiceAccountCredentialsSupplier must not be null"); @@ -196,12 +152,10 @@ public class GcpIamCredentialsAuthenticationOptions { * Configure an explicit service account id to use in GCP IAM calls. If none is * configured, falls back to using {@link ServiceAccountCredentials#getAccount()}. * @param serviceAccountId the service account id (email) to use - * @return {@code this} - * {@link GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder}. + * @return {@code this} {@link GoogleCloudIamAuthenticationOptionsBuilder}. * @since 2.1 */ - public GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder serviceAccountId( - String serviceAccountId) { + public GoogleCloudIamAuthenticationOptionsBuilder serviceAccountId(String serviceAccountId) { Assert.notNull(serviceAccountId, "Service account id may not be null"); @@ -209,17 +163,15 @@ public class GcpIamCredentialsAuthenticationOptions { } /** - * Configure an {@link GcpCredentialsAccountIdAccessor} to obtain the service + * Configure an {@link GoogleCredentialsAccountIdAccessor} to obtain the service * account id used in GCP IAM calls. If none is configured, falls back to using * {@link ServiceAccountCredentials#getAccount()}. * @param serviceAccountIdAccessor the service account id provider to use - * @return {@code this} - * {@link GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder}. - * @see GcpCredentialsAccountIdAccessor - * @since 2.1 + * @return {@code this} {@link GoogleCloudIamAuthenticationOptionsBuilder}. + * @see GoogleCredentialsAccountIdAccessor */ - GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder serviceAccountIdAccessor( - GcpCredentialsAccountIdAccessor serviceAccountIdAccessor) { + GoogleCloudIamAuthenticationOptionsBuilder serviceAccountIdAccessor( + GoogleCredentialsAccountIdAccessor serviceAccountIdAccessor) { Assert.notNull(serviceAccountIdAccessor, "GcpServiceAccountIdAccessor must not be null"); @@ -230,10 +182,9 @@ public class GcpIamCredentialsAuthenticationOptions { /** * Configure the name of the role against which the login is being attempted. * @param role must not be empty or {@literal null}. - * @return {@code this} - * {@link GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder}. + * @return {@code this} {@link GoogleCloudIamAuthenticationOptionsBuilder}. */ - public GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder role(String role) { + public GoogleCloudIamAuthenticationOptionsBuilder role(String role) { Assert.hasText(role, "Role must not be null or empty"); @@ -245,11 +196,9 @@ public class GcpIamCredentialsAuthenticationOptions { * Configure the {@link Duration} for the JWT expiration. This defaults to 15 * minutes and cannot be more than a hour. * @param jwtValidity must not be {@literal null}. - * @return {@code this} - * {@link GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder}. + * @return {@code this} {@link GoogleCloudIamAuthenticationOptionsBuilder}. */ - public GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder jwtValidity( - Duration jwtValidity) { + public GoogleCloudIamAuthenticationOptionsBuilder jwtValidity(Duration jwtValidity) { Assert.hasText(this.role, "JWT validity duration must not be null"); @@ -261,10 +210,9 @@ public class GcpIamCredentialsAuthenticationOptions { * Configure the {@link Clock} used to calculate epoch seconds until the JWT * expiration. * @param clock must not be {@literal null}. - * @return {@code this} - * {@link GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder}. + * @return {@code this} {@link GoogleCloudIamAuthenticationOptionsBuilder}. */ - public GcpIamCredentialsAuthenticationOptions.GcpIamCredentialsAuthenticationOptionsBuilder clock(Clock clock) { + public GoogleCloudIamAuthenticationOptionsBuilder clock(Clock clock) { Assert.hasText(this.role, "Clock must not be null"); @@ -278,7 +226,7 @@ public class GcpIamCredentialsAuthenticationOptions { */ public GcpIamCredentialsAuthenticationOptions build() { - Assert.notNull(this.credentialsSupplier, "GcpServiceAccountCredentialsSupplier must not be null"); + Assert.notNull(this.credentialsSupplier, "GoogleCredentialsSupplier must not be null"); Assert.notNull(this.role, "Role must not be null"); return new GcpIamCredentialsAuthenticationOptions(this.path, this.credentialsSupplier, this.role, diff --git a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpCredentialsAccountIdAccessor.java b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GoogleCredentialsAccountIdAccessor.java similarity index 94% rename from spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpCredentialsAccountIdAccessor.java rename to spring-vault-core/src/main/java/org/springframework/vault/authentication/GoogleCredentialsAccountIdAccessor.java index 6fa974a9..a2aaba18 100644 --- a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpCredentialsAccountIdAccessor.java +++ b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GoogleCredentialsAccountIdAccessor.java @@ -22,11 +22,11 @@ import com.google.auth.oauth2.GoogleCredentials; * Implementations are used by {@link GcpIamCredentialsAuthentication}. * * @author Andreas Gebauer - * @since 2.4 + * @since 2.3.2 * @see GcpIamCredentialsAuthentication */ @FunctionalInterface -public interface GcpCredentialsAccountIdAccessor { +public interface GoogleCredentialsAccountIdAccessor { /** * Get a the service account id (email) to be placed in the signed JWT. diff --git a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpCredentialsSupplier.java b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GoogleCredentialsSupplier.java similarity index 94% rename from spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpCredentialsSupplier.java rename to spring-vault-core/src/main/java/org/springframework/vault/authentication/GoogleCredentialsSupplier.java index bca78113..29539bc1 100644 --- a/spring-vault-core/src/main/java/org/springframework/vault/authentication/GcpCredentialsSupplier.java +++ b/spring-vault-core/src/main/java/org/springframework/vault/authentication/GoogleCredentialsSupplier.java @@ -26,11 +26,11 @@ import com.google.auth.oauth2.ServiceAccountCredentials; * authentication. Implementations are used by {@link GcpIamCredentialsAuthentication}. * * @author Andreas Gebauer - * @since 2.4 + * @since 2.3.2 * @see GcpIamCredentialsAuthentication */ @FunctionalInterface -public interface GcpCredentialsSupplier extends Supplier { +public interface GoogleCredentialsSupplier extends Supplier { /** * Exception-safe helper to get {@link ServiceAccountCredentials} from @@ -44,7 +44,7 @@ public interface GcpCredentialsSupplier extends Supplier { return getCredentials(); } catch (IOException e) { - throw new IllegalStateException("Cannot obtain GoogleCredential", e); + throw new IllegalStateException("Cannot obtain GoogleCredentials", e); } } diff --git a/spring-vault-core/src/test/java/org/springframework/vault/authentication/GcpIamCredentialsAuthenticationUnitTests.java b/spring-vault-core/src/test/java/org/springframework/vault/authentication/GcpIamCredentialsAuthenticationUnitTests.java index e81b3e34..a2567d12 100644 --- a/spring-vault-core/src/test/java/org/springframework/vault/authentication/GcpIamCredentialsAuthenticationUnitTests.java +++ b/spring-vault-core/src/test/java/org/springframework/vault/authentication/GcpIamCredentialsAuthenticationUnitTests.java @@ -67,11 +67,11 @@ class GcpIamCredentialsAuthenticationUnitTests { MockRestServiceServer mockRest; - private Server server; + Server server; - private ManagedChannel managedChannel; + ManagedChannel managedChannel; - private ServerCalls.UnaryMethod serverCall; + ServerCalls.UnaryMethod serverCall; @BeforeEach void before() throws IOException { diff --git a/src/main/asciidoc/new-features.adoc b/src/main/asciidoc/new-features.adoc index fe53ff86..158e35fb 100644 --- a/src/main/asciidoc/new-features.adoc +++ b/src/main/asciidoc/new-features.adoc @@ -12,6 +12,7 @@ * Login credentials for Kubernetes and PCF authentication are reloaded for each login attempt. * `SecretLeaseContainer` publishes `SecretLeaseRotatedEvent` instead of `SecretLeaseExpiredEvent` and `SecretLeaseCreatedEvent` on successful secret rotation. * `AbstractVaultConfiguration.threadPoolTaskScheduler()` bean type changed to `TaskSchedulerWrapper` instead of `ThreadPoolTaskScheduler`. +* Since 2.3.2: `GcpIamCredentialsAuthentication` [[new-features.2-2-0]] === What's new in Spring Vault 2.2 diff --git a/src/main/asciidoc/reference/authentication.adoc b/src/main/asciidoc/reference/authentication.adoc index 660d65d8..ae6f658f 100644 --- a/src/main/asciidoc/reference/authentication.adoc +++ b/src/main/asciidoc/reference/authentication.adoc @@ -485,7 +485,7 @@ auth backend allows Vault login by using existing GCP (Google Cloud Platform) IA GCP IAM authentication creates a signature in the form of a JSON Web Token (JWT) for a service account. A JWT for a service account is obtained by -calling GCP IAM's https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts/signJwt[`projects.serviceAccounts.signJwt`] API. The caller authenticates against GCP IAM +calling GCP IAM's https://cloud.google.com/iam/docs/reference/credentials/rest/v1/projects.serviceAccounts/signJwt[`projects.serviceAccounts.signJwt`] API. The caller authenticates against GCP IAM and proves thereby its identity. This Vault backend treats GCP as a Trusted Third Party. IAM credentials can be obtained from either the runtime environment @@ -504,10 +504,10 @@ class AppConfig extends AbstractVaultConfiguration { @Override public ClientAuthentication clientAuthentication() { - GcpIamAuthenticationOptions options = GcpIamAuthenticationOptions.builder() + GcpIamCredentialsAuthenticationOptions options = GcpIamCredentialsAuthenticationOptions.builder() .role(…).credential(GoogleCredentials.getApplicationDefault()).build(); - GcpIamAuthentication authentication = new GcpIamAuthentication(options, + GcpIamCredentialsAuthentication authentication = new GcpIamCredentialsAuthentication(options, restOperations()); } @@ -516,20 +516,23 @@ class AppConfig extends AbstractVaultConfiguration { ---- ==== -`GcpIamAuthenticationOptions` requires the Google Cloud Java SDK dependency -(`com.google.apis:google-api-services-iam` and `com.google.auth:google-auth-library-oauth2-http`) +`GcpIamCredentialsAuthenticationOptions` requires the Google Cloud Java SDK dependency +(`com.google.cloud:google-cloud-iamcredentials`) as the authentication implementation uses Google APIs for credentials and JWT signing. -You can configure the authentication via `GcpIamAuthenticationOptions`. +You can configure the authentication via `GcpIamCredentialsAuthenticationOptions`. NOTE: Google credentials require an OAuth 2 token maintaining the token lifecycle. All API -is synchronous therefore, `GcpIamAuthentication` does not support `AuthenticationSteps` which is +is synchronous therefore, `GcpIamCredentialsAuthentication` does not support `AuthenticationSteps` which is required for reactive usage. +NOTE: `GcpIamCredentialsAuthentication` uses the https://cloud.google.com/iam/docs/reference/credentials/rest/v1/projects.serviceAccounts/signJwt[IAM Credentials API] and is a replacement using the for the deprecated `GcpIamAuthentication` using the deprecated https://cloud.google.com/iam/docs/reference/rest/v1/projects.serviceAccounts/signJwt[IAM API]. + See also: * https://www.vaultproject.io/docs/auth/gcp.html[Vault Documentation: Using the GCP auth backend] -* https://cloud.google.com/iam/reference/rest/v1/projects.serviceAccounts/signJwt[GCP Documentation: projects.serviceAccounts.signJwt][[vault.authentication.gcpiam]] +* https://cloud.google.com/iam/docs/reference/credentials/rest/v1/projects.serviceAccounts/signJwt +* https://cloud.google.com/iam/docs/reference/rest/v1/projects.serviceAccounts/signJwt (deprecated) [[vault.authentication.pcf]] == PCF authentication