Skip to content

bug: Restore GCP metadata server support #3860

Description

@feloy

User Story

As a user running a Google Cloud SDK in an OpenShell sandbox, I want the GCP metadata endpoint to be available, so that the SDK can discover project and service-account information through its standard metadata flow.

Problem Statement

The GCP metadata server/emulator is no longer available in current sandbox runtimes. The google-cloud provider example requires the gcp-metadata platform adapter, but importing, updating, or attaching that profile fails with required platform adapter 'gcp-metadata' is unavailable in this build. Workloads that rely on GCP SDK metadata discovery therefore cannot use the provider as documented.

The implementation files crates/openshell-sandbox/src/google_cloud_metadata.rs and crates/openshell-sandbox/src/metadata_server.rs were removed in PR #2942 during the runtime split. The removal was raised in PR #3775, where maintainers requested a bug to track adding the capability back.

Impact / Why This Matters

Users cannot run GCP SDKs that expect the standard metadata service inside OpenShell, including flows that obtain project and service-account details through metadata discovery. They must replace that flow with manually configured values or credentials, which is not equivalent for workloads designed to use metadata-based authentication and reduces portability across GCP environments.

Acceptance Criteria

  • OpenShell provides the documented GCP metadata endpoint to sandbox workloads on supported runtimes.
  • A GCP SDK can perform metadata discovery, including retrieving the expected project/service-account metadata, using the standard metadata request flow.
  • Automated coverage verifies the metadata behavior and prevents an unsupported gcp-metadata profile from being presented as usable.

Reproduction Steps

  1. Use a current OpenShell build containing the runtime split from PR feat(isolation): implement the RFC 0012 sandbox architecture #2942.
  2. Import or attach the google-cloud provider profile, which declares required_platform_adapter: gcp-metadata.
  3. Observe the required platform adapter 'gcp-metadata' is unavailable in this build error. In builds/configurations where the profile can be attached, run a GCP SDK that queries http://metadata.google.internal/computeMetadata/v1/ with the Metadata-Flavor: Google header; metadata discovery is unavailable.

Environment

Logs

required platform adapter 'gcp-metadata' is unavailable in this build

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions