Repository navigation
feat(auth): add DISABLE_BOUND_ID_TOKEN option to opt out of certificate-bound ID tokens - #14559
Merged
macastelaz merged 5 commits intoOct 10, 2026
Conversation
Contributor
There was a problem hiding this comment.
Code Review
This pull request introduces AgentIdentityUtils to support Agent Identity runtime certificate discovery and token binding, enabling ComputeEngineCredentials to request certificate-bound access tokens from the GCE metadata server. Feedback on the changes highlights several locations in ComputeEngineCredentials where HttpResponse connections are not disconnected or closed upon receiving a 404 status code, potentially leading to HTTP connection leaks.
macastelaz
force-pushed
the
defer-bound-id-tokens
branch
from
October 6, 2026 15:04
8b9072e to
dbf54df
Compare
This was referenced Oct 6, 2026
macastelaz
added a commit
that referenced
this pull request
Oct 6, 2026
…igquery pom (#14587) ## Why Every PR into `agentic-identities-bound-token` is currently failing CI (for example #14559 and #14557, about 35 jobs each) with: ``` [ERROR] 'dependencies.dependency.(groupId:artifactId:type:classifier)' must be unique: com.google.cloud:google-cloud-storage:jar -> duplicate declaration of version (?) [ERROR] 'dependencies.dependency.(groupId:artifactId:type:classifier)' must be unique: com.google.cloud:google-cloud-datacatalog:jar -> duplicate declaration of version 1.102.0-SNAPSHOT [ERROR] The build could not read 1 project ``` `java-bigquery/google-cloud-bigquery/pom.xml` declares `google-cloud-storage` and `google-cloud-datacatalog` twice in `<dependencies>`. This has been the case for a while, but Maven 3.9 only logged a `[WARNING]`. The GitHub `ubuntu-24.04` runner image `20261004` upgraded Maven from 3.9.16 to 3.10.0, which treats it as an error, so any job that loads the reactor now fails immediately. ## Change Remove the second declaration of each dependency (11 lines, one file): - `google-cloud-storage`: drops the later test-scoped entry. This is the same change as #14586 on `main`. - `google-cloud-datacatalog`: drops the second, identical test-scoped entry. `main` no longer has this dependency in this pom, so #14586 doesn't need it. ## Verification - `mvn help:effective-pom` on the module before and after: the effective `<dependencies>` section is identical. `google-cloud-storage` stays test-scoped because the parent's `dependencyManagement` sets `<scope>test</scope>`, and the two datacatalog entries were identical. - Each artifact now appears once in `<dependencies>`; the pom parses as valid XML.
…bound ID tokens ComputeEngineCredentials requests certificate-bound ID tokens by default when an agent identity certificate is available. Bound ID tokens are only accepted by targets that authenticate the caller over mTLS with the same certificate, so targets reached over standard HTTPS (for example a Cloud Run *.run.app URL or a custom domain) reject them with 401. Add IdTokenProvider.Option.BIND_ID_TOKEN_FALSE so callers can request an unbound ID token per target, through idTokenWithAudience() or IdTokenCredentials.Builder.setOptions(). When the option is present, the certificate lookup is skipped and the identity endpoint is called with a plain GET. Without it, behavior is unchanged: ID tokens are bound whenever a certificate is available and GOOGLE_API_ENABLE_RUNTIME_BOUND_TOKEN is not false. Other credential types ignore the option.
macastelaz
force-pushed
the
defer-bound-id-tokens
branch
from
October 6, 2026 17:08
dbf54df to
f58f3a3
Compare
macastelaz
marked this pull request as ready for review
October 6, 2026 17:21
lqiu96
reviewed
Oct 7, 2026
lqiu96
reviewed
Oct 7, 2026
lqiu96
approved these changes
Oct 9, 2026
lqiu96
left a comment
Member
There was a problem hiding this comment.
LGTM. FYi, I think you can update the PR and the CI should pass now
macastelaz
merged commit Oct 10, 2026
1de87fd
into
googleapis:agentic-identities-bound-token
282 of 284 checks passed
macastelaz
added a commit
that referenced
this pull request
Oct 10, 2026
…14557) > [!IMPORTANT] > **Merge after #14559**, which adds `IdTokenProvider.Option.DISABLE_BOUND_ID_TOKEN` referenced here. Both must merge before the `agentic-identities-bound-token` feature branch is merged to `main`. ## What this adds Docs only; no code changes. - **`ComputeEngineCredentials` class Javadoc**: adds a brief summary noting that when a workload certificate for an agent identity is available, `ComputeEngineCredentials` requests certificate-bound access tokens and ID tokens by default, with pointers to `IdTokenProvider.Option.DISABLE_BOUND_ID_TOKEN` and the [Google Auth Library guide](https://cloud.google.com/java/getting-started/getting-started-with-google-auth-library). - The full "Certificate-bound tokens for agent identities" user guide section (covering environment variables, per-target ID token opt-out, and the ADK for Java limitation) is being added to the DevSite `getting-started-with-google-auth-library` page (`cl/996749889`) alongside the Cloud Run documentation (`cl/990396526`). ## Release notes `google-auth-library-java/CHANGELOG.md` is generated, so release notes come from commit messages. Suggested text for the `BEGIN_COMMIT_OVERRIDE` block of the feature-branch → `main` merge PR: ``` feat(auth): request certificate-bound tokens for agent identities by default. Set GOOGLE_API_ENABLE_RUNTIME_BOUND_TOKEN=false to opt out. feat(auth): add IdTokenProvider.Option.DISABLE_BOUND_ID_TOKEN to request unbound ID tokens for specific targets. docs(auth): known limitation: ADK for Java doesn't support mTLS yet; agents that use it must set GOOGLE_API_ENABLE_RUNTIME_BOUND_TOKEN=false. ``` ## Testing - `google-java-format` and `javadoc:javadoc` pass.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Important
This must merge before the
agentic-identities-bound-tokenfeature branch is merged tomain. Docs PR #14557 documents this option.Why
When an agent identity certificate is available,
ComputeEngineCredentialsrequests certificate-bound ID tokens by default. A bound ID token is only accepted by targets that authenticate the caller over mTLS with the same certificate. Targets reached over standard HTTPS, such as a Cloud Run service's*.run.appURL or a custom domain, reject it with401 Unauthorized.Per the ID token binding 1-pager (Sep 30 decision), ID tokens stay bound by default, and callers get a per-target
bind_id_tokensetting to turn binding off where needed. The process-wide opt-out (GOOGLE_API_ENABLE_RUNTIME_BOUND_TOKEN=false) is unchanged.What changes
New
IdTokenProvider.Option.DISABLE_BOUND_ID_TOKEN. Callers pass it per target, the same way asFORMAT_FULLandLICENSES_TRUE:ComputeEngineCredentials.idTokenWithAudience(): with the option, the certificate lookup is skipped and the identity endpoint is called with a plain GET. Without it, behavior is unchanged (bound whenever a certificate is available and binding isn't turned off by the env var).Other credential types (
ServiceAccountCredentials,ImpersonatedCredentials,UserCredentials) already ignore options they don't use, so the same code works outside agent identity environments.Access tokens are unaffected.
API shape
Optionis a set of on/off flags rather than a value, so this adds only the "off" flag (DISABLE_BOUND_ID_TOKEN). Leaving it unset means "auto", which currently means bound. This matches the 1-pager's tri-state (unset = auto) without adding an "enable" flag that would do nothing today; one can be added later without breaking callers if "auto" starts deciding per target. Python exposes the same control asbind_id_token: Optional[bool](googleapis/google-cloud-python#18559).Tests
Unit tests
New
ComputeEngineCredentialsTestcases, all with an agent identity certificate present and binding enabled:idTokenWithAudience_disableBoundIdToken_requestsUnboundToken: GET, no request body, no forcedformat=full.idTokenWithAudience_disableBoundIdTokenWithFormatFull_requestsUnboundFullToken: still GET;format=fullis kept when the caller asks for it.idTokenWithAudience_disableBoundIdToken_skipsCertificateLookup: with a certificate config pointing to a missing file, the default request fails, but the opted-out request succeeds, which shows the certificate is never read.idTokenCredentials_withDisableBoundIdTokenOption_requestsUnboundToken: the option set onIdTokenCredentialsreachesComputeEngineCredentials.The existing bound-ID-token tests are unchanged and still pass. Full
oauth2_httpsuite: 1064 tests, 0 failures.fmtis clean.Live test on GKE
Run on a GKE cluster with agent identity enabled, using a test-only local merge of this PR with #14595 (GKE support) and #14556 (already on the base branch). A single process fetches ID tokens through
IdTokenCredentialsfromComputeEngineCredentials(ADC) and sends them to an agent-to-agent receiver pod. The receiver accepts only bound tokens over mTLS (whosecnfmust match the client certificate), and only unbound tokens over plain HTTP.GOOGLE_API_ENABLE_RUNTIME_BOUND_TOKEN=falseDISABLE_BOUND_ID_TOKENcnf); receiver: plain HTTP 200, mTLS 401cnf= certificate leaf); receiver: mTLS 200The option unbinds only the ID token it's set on. Other targets and access tokens are unaffected, and it's harmless when binding is already off.
Internal links (Googlers only): results · harness · cluster setup and manifests (shared with #14595)