Skip to content

Add GCS HMAC key-pair auth as an alternative to service-account JSON - #29

Open
sandshoes wants to merge 1 commit into
mainfrom
tommy/protm-2261-gcs-hmac-connector
Open

sandshoes wants to merge 1 commit into
mainfrom
tommy/protm-2261-gcs-hmac-connector

Conversation

@sandshoes

Copy link
Copy Markdown
Contributor

Summary

  • The Forward CLI distinguishes gcloud_storage / gcloud_storage_hmac / gcloud_storage_sa connector types; define_gcs_connection previously only supported the service-account JSON case.
  • Adds HMAC key-pair auth (hmac_access_id/hmac_secret) as a mutually-exclusive alternative to service_account_credentials_json, mirroring the existing arn vs. access_key/secret pattern already used for S3 connections in this SDK (one connection abstraction, pluggable auth, single TYPE gcs datafile — consistent with how S3's two auth variants both stay under TYPE s3).
  • Threaded through all three layers: schema (define_gcs_connection validation), forward generator (GCS_HMAC_ACCESS_ID/GCS_HMAC_SECRET datafile directives), and the reverse migrate parser + TypeScript emitter, for full round-trip support.

Closes PROTM-2261: https://linear.app/tinybird/issue/PROTM-2261/python-sdk-add-gcs-hmacservice-account-connector-distinction

Checklist

  • CI is green (lint, typecheck, test)
  • pre-commit run --all-files passes locally (gitleaks step fails in this sandbox on an unrelated SSL/network error fetching its pre-commit env; not a code issue)
  • Tests were added or updated when behavior changed
  • Public API / typing changes were reviewed
  • Documentation was updated (README.md) with an HMAC connection example
  • Breaking changes are clearly documented (none — existing service-account usage is unaffected)
  • CHANGELOG.md was updated when user-facing behavior changed

`define_gcs_connection` now accepts `hmac_access_id`/`hmac_secret` as
a mutually-exclusive alternative to `service_account_credentials_json`,
mirroring the Forward CLI's gcloud_storage_hmac/gcloud_storage_sa split
and the existing arn-vs-access_key/secret pattern already used for S3.

Threaded through the schema layer (define_gcs_connection validation),
the forward generator (GCS_HMAC_ACCESS_ID/GCS_HMAC_SECRET datafile
directives), and the reverse migrate parser/TS emitter for full
round-trip support.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant