Pyrite::Providers::GCPKMS
Inherits Pyrite::Provider < Reference < Object
Provider for Google Cloud Run, Google Kubernetes Engine (GKE), and Google Compute Engine (GCE).
Authenticates via the ambient GCP Metadata Server (169.254.169.254) to obtain an OIDC / OAuth2
access token for the default attached Service Account, and calls the Google Cloud KMS REST API
(https://cloudkms.googleapis.com/v1/{KMS_RESOURCE}:decrypt) to unseal the payload.
Prerequisites
- Google Cloud Service Account with
roles/cloudkms.cryptoKeyDecrypteron the target key. - Environment variable
$KMS_KEY_RESOURCEin format:projects/{project}/locations/{location}/keyRings/{keyRing}/cryptoKeys/{cryptoKey}
Example
provider = Pyrite::Providers::GCPKMS.new("projects/my-prod/locations/global/keyRings/ring/cryptoKeys/app-key")
config = Pyrite.bootstrap!(AppConfig, provider: provider)
Constants
METADATA_HOST = "metadata.google.internal"
Hostname of the Google Compute Engine metadata server
METADATA_PATH = "/computeMetadata/v1/instance/service-accounts/default/token"
API path for default service account access token retrieval