techlite/fetch-gcp-secret-gcloud
1.0.0
privilege mediumgcloud CLI on the official slim image
implementation
How to choose it
implementation: techlite/fetch-gcp-secret-gcloudIt satisfies the contracttechlite/fetch-gcp-secret^1.0.0 → 1.0.0
This version was published without a description.
What actually runs
- Image
google/cloud-sdk:slim- Entrypoint
sh -c set -eu name=$(sed -n 's/.*"secret":"\([^"]*\)".*/\1/p' "$OREN_INPUT_PATH") project=$(sed -n 's/.*"project":"\([^"]*\)".*/\1/p' "$OREN_INPUT_PATH") version=$(sed -n 's/.*"version":"\([^"]*\)".*/\1/p' "$OREN_INPUT_PATH") gcloud --quiet secrets versions access "${version:-latest}" \ --secret="$name" ${project:+--project="$project"} > /tmp/payload python3 -c 'import json; print(json.dumps({"value": open("/tmp/payload").read()}))' \ > "$OREN_OUTPUT_PATH"
Where the dependencies appear
Inside the container. This is what a compatible worker has to expect — knowing it asks for a credential is not knowing where it reads it.
| dependency | where | |
|---|---|---|
gcloudToken | $CLOUDSDK_AUTH_ACCESS_TOKENas an environment variable |