Skip to content

fix: keep a separate Google credentials file for each secret key - #309

Open
armru wants to merge 1 commit into
mainfrom
dev/gcs-credentials-per-store
Open

armru wants to merge 1 commit into
mainfrom
dev/gcs-credentials-per-store

Conversation

@armru

@armru armru commented Sep 30, 2026

Copy link
Copy Markdown
Member

A single process can run barman-cloud commands for different object stores at the same time. In the plugin sidecar, for instance, the designated primary of a replica cluster archives WAL to its own object store while restoring it from the source one. The Google application credentials were always materialized in /controller/.application_credentials.json, so with two Google Cloud Storage object stores using different credentials a command could run with the identity of the other object store, and an object store relying on the GKE environment rewrote the shared file with empty content while the other commands were reading it.

Each credentials file is now written under /controller/.google-credentials/<secret>/<key>, GOOGLE_APPLICATION_CREDENTIALS points at it, and the writes are serialized, because fileutils.WriteFileAtomic names its temporary file after the current second. The GKE environment does not touch any file anymore.

This is the same problem fixed for the SSE-C customer keys in #284.

A single process can run barman-cloud commands for different object
stores at the same time. A replica cluster, for instance, archives WAL to
its own object store while restoring it from the source one. The Google
application credentials were always written to the same file, so a
command could run with the credentials of another object store, and an
object store using the GKE environment emptied the file the other
commands were reading.

Write each credentials file to a path that depends on the referenced
secret and key, point GOOGLE_APPLICATION_CREDENTIALS at it, and serialize
the writes. The GKE environment no longer touches any file.

Signed-off-by: Armando Ruocco <armando.ruocco@enterprisedb.com>
@leonardoce
leonardoce force-pushed the dev/gcs-credentials-per-store branch from 24110fd to 120366b Compare October 2, 2026 08:15
@leonardoce

leonardoce commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

I opened cloudnative-pg/machinery#325 to fix the reason why we need googleCredentialsMutex.
When it is merged, we can remove it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants