feat: Add agent authentication based on instance ID (#336)

* feat: Add agent authentication based on instance ID

Each cloud has it's own unique instance identity signatures, which
can be used for zero-token authentication. This change adds support
for tracking by "instance_id", and automatically authenticating
with Google Cloud.

* Add test for CLI

* Fix workspace agent request name

* Fix race with adding to wait group

* Fix name of instance identity token
This commit is contained in:
Kyle Carberry
2022-02-21 20:36:29 +00:00
committed by GitHub
parent 67613da86d
commit 8958b641e9
41 changed files with 752 additions and 251 deletions
+11 -2
View File
@@ -8,6 +8,7 @@ import (
"io"
"os"
"path/filepath"
"reflect"
"strings"
"github.com/hashicorp/terraform-exec/tfexec"
@@ -245,9 +246,17 @@ func (t *terraform) runTerraformApply(ctx context.Context, terraform *tfexec.Ter
resources := make([]*proto.Resource, 0)
if state.Values != nil {
for _, resource := range state.Values.RootModule.Resources {
var instanceID string
if gcpInstanceID, ok := resource.AttributeValues["instance_id"]; ok {
instanceID, ok = gcpInstanceID.(string)
if !ok {
return xerrors.Errorf("invalid type for instance_id property: %s", reflect.TypeOf(gcpInstanceID).String())
}
}
resources = append(resources, &proto.Resource{
Name: resource.Name,
Type: resource.Type,
Name: resource.Name,
Type: resource.Type,
InstanceId: instanceID,
})
}
}