feat: add support for GAR image-pull auth via GCP identity - #10
Draft
PeteE wants to merge 2 commits into
Draft
Conversation
PeteE
force-pushed
the
pete-gcp-pull-auth
branch
from
July 15, 2026 15:51
d8aee45 to
899dc1e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ImagePullAuthAugmenterprovider interface (src/cloud-providers/types.go) that lets a cloud provider contribute registry credentials derived from its own cloud identity, merged into theauth.jsonshipped to the podvm alongside any operator-suppliedimagePullSecrets.src/cloud-providers/gcp/imagepullauth.go): mints a short-lived OAuth token (via ADC or an impersonated service account) scoped for Artifact Registry / GCR (us-central1-docker.pkg.dev-style hosts), so podvm image pulls from GAR can authenticate using CAA's own GKE Workload Identity instead of requiring animagePullSecret.GCP_PULL_REGISTRY(registry hostname to authenticate against) andGCP_PULL_IMPERSONATE(optional least-privilege SA to impersonate when minting the token), withConfigVerifiervalidation to fail fast on misconfiguration (impersonation set without a registry, or a registry value that isn't a bare hostname).mergeDockerAuthsinpkg/adaptor/cloud/cloud.goto combine the operator'simagePullSecrets-derivedauth.jsonwith the provider-derived auth (provider auth wins on host conflicts); augmentation failures are non-fatal and fall back to the existing behavior.Test plan
go build ./.../ existing unit tests passGCP_PULL_REGISTRYset to a GAR host and verify podvm image pulls succeed without animagePullSecretGCP_PULL_IMPERSONATEpath mints a token scoped to the impersonated SAConfigVerifierrejectsGCP_PULL_IMPERSONATEwithoutGCP_PULL_REGISTRY, and rejects aGCP_PULL_REGISTRYcontaining/or@