Package com.google.cloud.hadoop.util
Class HadoopCredentialsConfiguration
java.lang.Object
com.google.cloud.hadoop.util.HadoopCredentialsConfiguration
The Hadoop credentials configuration.
When reading configuration this class makes use of a list of key prefixes that are each applied to key suffixes to create a complete configuration key. There is a base prefix of 'google.cloud.' that is included by the builder for each configuration key suffix. When constructing, other prefixes can be specified. Prefixes specified later can be used to override the values of previously set values. In this way a set of global credentials can be specified for most connectors with an override specified for any connectors that need different credentials.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic final classstatic enumEnumerates all supported authentication types -
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final HadoopConfigurationProperty<Class<? extends AccessTokenProvider>>Key suffix used to configureAccessTokenProviderthat will be used to generateAccessTokenProvider.AccessTokens.static final HadoopConfigurationProperty<String>Configuration key for defining the OAUth2 client ID.static final HadoopConfigurationProperty<RedactedString>Configuration key for defining the OAUth2 client secret.static final HadoopConfigurationProperty<RedactedString>Configuration key for defining the OAuth2 refresh token.Key suffix used to configure authentication type.static final StringAll instances constructed using the builder will usegoogle.cloudas the first prefix checked.static final Stringstatic final HadoopConfigurationProperty<Map<String,String>> Key prefix for the group identifier associated with the service account to impersonate when accessing GCS.static final HadoopConfigurationProperty<String>Key suffix used to configure the impersonating service account with which to call GCS API to get access token.static final HadoopConfigurationProperty<String>Key suffix for setting a proxy for the connector to use to connect to GCS.static final HadoopConfigurationProperty<RedactedString>Key suffix for setting a proxy password for the connector to use to authenticate with proxy used to connect to GCS.static final HadoopConfigurationProperty<RedactedString>Key suffix for setting a proxy username for the connector to use to authenticate with proxy used to connect to GCS.static final HadoopConfigurationProperty<Long>Key suffix for setting the read timeout for HTTP request.static final HadoopConfigurationProperty<String>Key suffix used to configure the path to a JSON file containing a Service Account key and identifier (email).static final HadoopConfigurationProperty<String>Key suffix for setting a token server URL to use to refresh OAuth token.static final HadoopConfigurationProperty<Map<String,String>> Key prefix for the user identifier associated with the service account to impersonate when accessing GCS.static final HadoopConfigurationProperty<String>Key suffix used to configure the path to a JSON file containing a workload identity federation, i.e. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptiongetConfigKeyPrefixes(String... keyPrefixes) Returns full list of config prefixes that will be resolved based on the order in returned list.static com.google.auth.oauth2.GoogleCredentialsgetCredentials(org.apache.hadoop.conf.Configuration config, String... keyPrefixesVararg) Get the credentials for the configuredHadoopCredentialsConfiguration.AuthenticationTypestatic com.google.auth.oauth2.GoogleCredentialsgetImpersonatedCredentials(org.apache.hadoop.conf.Configuration config, com.google.auth.oauth2.GoogleCredentials sourceCredentials, String... keyPrefixesVararg) Create aImpersonatedCredentialsbased on service account to impersonate configuration
-
Field Details
-
BASE_KEY_PREFIX
All instances constructed using the builder will usegoogle.cloudas the first prefix checked. Other prefixes can be added and will override values in thegoogle.cloudprefix.- See Also:
-
CLOUD_PLATFORM_SCOPE
- See Also:
-
AUTHENTICATION_TYPE_SUFFIX
public static final HadoopConfigurationProperty<HadoopCredentialsConfiguration.AuthenticationType> AUTHENTICATION_TYPE_SUFFIXKey suffix used to configure authentication type. -
SERVICE_ACCOUNT_JSON_KEYFILE_SUFFIX
Key suffix used to configure the path to a JSON file containing a Service Account key and identifier (email). Technically, this could be a JSON containing a non-service account user, but this setting is only used in the service account flow and is namespaced as such. -
WORKLOAD_IDENTITY_FEDERATION_CREDENTIAL_CONFIG_FILE_SUFFIX
public static final HadoopConfigurationProperty<String> WORKLOAD_IDENTITY_FEDERATION_CREDENTIAL_CONFIG_FILE_SUFFIXKey suffix used to configure the path to a JSON file containing a workload identity federation, i.e. external account credential configuration. Technically, this could be a JSON containing an service account impersonation url and credential source. but this setting is only used in the workload identity federation flow and is namespaced as such. -
ACCESS_TOKEN_PROVIDER_SUFFIX
public static final HadoopConfigurationProperty<Class<? extends AccessTokenProvider>> ACCESS_TOKEN_PROVIDER_SUFFIXKey suffix used to configureAccessTokenProviderthat will be used to generateAccessTokenProvider.AccessTokens. -
IMPERSONATION_SERVICE_ACCOUNT_SUFFIX
Key suffix used to configure the impersonating service account with which to call GCS API to get access token. -
USER_IMPERSONATION_SERVICE_ACCOUNT_SUFFIX
public static final HadoopConfigurationProperty<Map<String,String>> USER_IMPERSONATION_SERVICE_ACCOUNT_SUFFIXKey prefix for the user identifier associated with the service account to impersonate when accessing GCS. -
GROUP_IMPERSONATION_SERVICE_ACCOUNT_SUFFIX
public static final HadoopConfigurationProperty<Map<String,String>> GROUP_IMPERSONATION_SERVICE_ACCOUNT_SUFFIXKey prefix for the group identifier associated with the service account to impersonate when accessing GCS. -
TOKEN_SERVER_URL_SUFFIX
Key suffix for setting a token server URL to use to refresh OAuth token. -
PROXY_ADDRESS_SUFFIX
Key suffix for setting a proxy for the connector to use to connect to GCS. The proxy must be an HTTP proxy of the form "host:port". -
PROXY_USERNAME_SUFFIX
Key suffix for setting a proxy username for the connector to use to authenticate with proxy used to connect to GCS. -
PROXY_PASSWORD_SUFFIX
Key suffix for setting a proxy password for the connector to use to authenticate with proxy used to connect to GCS. -
READ_TIMEOUT_SUFFIX
Key suffix for setting the read timeout for HTTP request. -
AUTH_CLIENT_ID_SUFFIX
Configuration key for defining the OAUth2 client ID. Required when the authentication type is USER_CREDENTIALS -
AUTH_CLIENT_SECRET_SUFFIX
Configuration key for defining the OAUth2 client secret. Required when the authentication type is USER_CREDENTIALS -
AUTH_REFRESH_TOKEN_SUFFIX
Configuration key for defining the OAuth2 refresh token. Required when the authentication type is USER_CREDENTIALS
-
-
Constructor Details
-
HadoopCredentialsConfiguration
protected HadoopCredentialsConfiguration()
-
-
Method Details
-
getConfigKeyPrefixes
Returns full list of config prefixes that will be resolved based on the order in returned list. -
getCredentials
public static com.google.auth.oauth2.GoogleCredentials getCredentials(org.apache.hadoop.conf.Configuration config, String... keyPrefixesVararg) throws IOException Get the credentials for the configuredHadoopCredentialsConfiguration.AuthenticationType- Throws:
IllegalStateException- if configuredHadoopCredentialsConfiguration.AuthenticationTypeis not recognizedIOException
-
getImpersonatedCredentials
public static com.google.auth.oauth2.GoogleCredentials getImpersonatedCredentials(org.apache.hadoop.conf.Configuration config, com.google.auth.oauth2.GoogleCredentials sourceCredentials, String... keyPrefixesVararg) throws IOException Create aImpersonatedCredentialsbased on service account to impersonate configuration- Throws:
IOException
-