Skip to content

feat: add --login-token flag for separate IAM database authentication - #958

Merged
blueberry121518 merged 2 commits into
mainfrom
login-token-specification
Jul 15, 2026
Merged

blueberry121518 merged 2 commits into
mainfrom
login-token-specification

Conversation

@blueberry121518

@blueberry121518 blueberry121518 commented Jul 14, 2026 •

Copy link
Copy Markdown
Contributor

Overview

Adds a --login-token flag that lets the proxy use a separate OAuth2 token for
IAM database authentication login, distinct from --token, which authenticates
AlloyDB Admin API calls. This keeps the API credentials (Unnecessary scopes) out of the database
login path, supporting least-privilege access.

Requires --token and --auto-iam-authn. When unset, existing behavior is
unchanged, and the proxy logs a warning suggesting the new flag.

Fixes #848.

Testing

  • Unit tests for flag parsing and validation.
  • Verified manually against a live AlloyDB instance (public IP, IAM authn):
    • valid --token + valid --login-token → connects
    • valid --token + corrupted --login-token → rejected at the IAM check, proving no silent fallback to --token
    • valid --token only → connects via the existing fallback path, warning logged

@blueberry121518
blueberry121518 marked this pull request as ready for review July 14, 2026 20:46
@blueberry121518
blueberry121518 requested a review from a team as a code owner July 14, 2026 20:46
@blueberry121518
blueberry121518 marked this pull request as draft July 14, 2026 20:49
@blueberry121518
blueberry121518 marked this pull request as ready for review July 14, 2026 21:39
@nancynh nancynh assigned enocom and nancynh and unassigned rhatgadkar-goog Jul 14, 2026
Comment thread cmd/root.go Outdated
}
if conf.LoginToken != "" && conf.Token == "" {
return newBadCommandError("cannot specify --login-token without --token")
}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think we need to force the user to specify both --token and --login-token here. The --login-token flag should be optional for the customer to use when they want to specify a specific tokens for interacting with our API vs only being able to login into the DB.

Be sure to also update the flag description in the various spots as well

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I see this makes sense. I did more research, and it seems that, especially since it is not a security concern, it does not warrant a warning, and especially not a hard fail.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

commit fixed

Comment thread internal/proxy/proxy.go Outdated
oauth2.StaticTokenSource(&oauth2.Token{AccessToken: c.LoginToken}),
))
case c.Token != "" || c.ImpersonationChain != "":
l.Infof("Warning: reusing the configured API credential for IAM database authentication login. " +

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On a similar thought with the comment above - if the --login-token flag is optional then we should change this log to be a Note: instead of a Warning:, and could drop the second sentence since it's covered already in the help/README text

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Makes sense. Not a warning but just a note to let users know. Keep warnings for real threats that should be made known

@blueberry121518
blueberry121518 force-pushed the login-token-specification branch from fba809f to 2d2947a Compare July 15, 2026 05:37

@nancynh nancynh left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@enocom enocom left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please fix the two minor formatting issues noted below before merging.

Comment thread cmd/root.go Outdated
localFlags.StringVarP(&c.conf.Token, "token", "t", "",
"Bearer token used for authorization.")
localFlags.StringVar(&c.conf.LoginToken, "login-token", "",
"Bearer token used as a separate credential for IAM database authentication login. Only used when --auto-iam-authn is enabled.")

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is going to wrap in a small terminal window. Would you format this help string as we've done above and below?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Got it thanks!

Comment thread docs/cmd/alloydb-auth-proxy.md Outdated
the cached copy has expired. Use this setting in environments where the
CPU may be throttled and a background refresh cannot run reliably
(e.g., Cloud Run)
--login-token string Bearer token used as a separate credential for IAM database authentication login. Only used when --auto-iam-authn is enabled.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditto here on wrapping. We try to make this easy to read in the terminal on smaller screens.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Got it thanks!

@blueberry121518
blueberry121518 merged commit 33a4171 into main Jul 15, 2026
22 checks passed
@blueberry121518
blueberry121518 deleted the login-token-specification branch July 15, 2026 22:29
@enocom enocom changed the title feat: add --login-token flag for separate IAM database authentication… feat: add --login-token flag for separate IAM database authentication Jul 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add support for specifying login-token

4 participants