Skip to content

Accept service-account-json in the CAS config flags - #3252

Open
frankfeng579 wants to merge 1 commit into
google:mainfrom
frankfeng579:use-specified-service-account-key
Open

frankfeng579 wants to merge 1 commit into
google:mainfrom
frankfeng579:use-specified-service-account-key

Conversation

@frankfeng579

@frankfeng579 frankfeng579 commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Allow service-account-json in the flags section of the CAS downloader
config (/etc/casdownloader/config.json by default). When set, cvd passes it
to casdownloader instead of -use-adc. Previously this key was silently ignored
as an auto-populated flag.

This lets hosts authenticate casdownloader without relying on
GOOGLE_APPLICATION_CREDENTIALS reaching cvd, e.g. when cvd is launched by
the host orchestrator. The key is used only for CAS; Android Build API
credentials are unaffected.

Credential precedence

  1. flags.service-account-json from the CAS config (CAS-specific).
  2. --service_account_filepath (existing reuse of the Build API key, which may
    not have CAS access; now logged as a warning when used).
  3. Application default credentials (-use-adc).

Exactly one credential flag is passed, as casdownloader requires. A configured
key that doesn't exist disables CAS with a clear error instead of silently
falling back; downloads then proceed from Android Build as before.

Testing

  • New unit tests in cas_downloader_test.cpp: key from config, config
    overrides --service_account_filepath, missing configured key disables CAS.
    bazel test //cuttlefish/host/libs/web/cas/... passes.
  • Manual cvd fetch of a git_main phone build:
    • no key configured: -use-adc, image downloaded from CAS;
    • key configured: only -service-account-json=<key>, image downloaded from CAS;
    • nonexistent key configured: CAS disabled with the "not found" error, fetch
      completed via Android Build.

Allow "service-account-json" in the "flags" section of the CAS
downloader config (/etc/casdownloader/config.json by default). It was
previously ignored as an auto-populated flag. When set, cvd passes it to
casdownloader instead of -use-adc.

This lets hosts authenticate casdownloader without depending on
GOOGLE_APPLICATION_CREDENTIALS reaching cvd, e.g. when cvd is run by the
host orchestrator, whose environment is controlled by its init script.
The configured key is only used by casdownloader for CAS; Android Build
API credentials are unaffected.

Credential precedence: service-account-json from the config, which is
specific to CAS; then the existing reuse of the Android Build API
service account (--service_account_filepath), which may not have CAS
access and is logged as a warning when used; then application default
credentials. casdownloader requires exactly one credential flag, so the
config value is removed from the pass-through flags and emitted by the
credential selection. A configured key that does not exist is an error,
which disables CAS with a clear reason rather than falling back to other
credentials.

Assisted-by: Jetski:Claude

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants