1# Copyright 2016 Google LLC
2#
3# Licensed under the Apache License, Version 2.0 (the "License");
4# you may not use this file except in compliance with the License.
5# You may obtain a copy of the License at
6#
7# http://www.apache.org/licenses/LICENSE-2.0
8#
9# Unless required by applicable law or agreed to in writing, software
10# distributed under the License is distributed on an "AS IS" BASIS,
11# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12# See the License for the specific language governing permissions and
13# limitations under the License.
14
15"""Environment variables used by :mod:`google.auth`."""
16
17PROJECT = "GOOGLE_CLOUD_PROJECT"
18"""Environment variable defining default project.
19
20This used by :func:`google.auth.default` to explicitly set a project ID. This
21environment variable is also used by the Google Cloud Python Library.
22"""
23
24LEGACY_PROJECT = "GCLOUD_PROJECT"
25"""Previously used environment variable defining the default project.
26
27This environment variable is used instead of the current one in some
28situations (such as Google App Engine).
29"""
30
31GOOGLE_CLOUD_QUOTA_PROJECT = "GOOGLE_CLOUD_QUOTA_PROJECT"
32"""Environment variable defining the project to be used for
33quota and billing."""
34
35CREDENTIALS = "GOOGLE_APPLICATION_CREDENTIALS"
36"""Environment variable defining the location of Google application default
37credentials."""
38
39# The environment variable name which can replace ~/.config if set.
40CLOUD_SDK_CONFIG_DIR = "CLOUDSDK_CONFIG"
41"""Environment variable defines the location of Google Cloud SDK's config
42files."""
43
44# These two variables allow for customization of the addresses used when
45# contacting the GCE metadata service.
46GCE_METADATA_HOST = "GCE_METADATA_HOST"
47"""Environment variable providing an alternate hostname or host:port to be
48used for GCE metadata requests.
49
50This environment variable was originally named GCE_METADATA_ROOT. The system will
51check this environemnt variable first; should there be no value present,
52the system will fall back to the old variable.
53"""
54
55GCE_METADATA_ROOT = "GCE_METADATA_ROOT"
56"""Old environment variable for GCE_METADATA_HOST."""
57
58GCE_METADATA_IP = "GCE_METADATA_IP"
59"""Environment variable providing an alternate ip:port to be used for ip-only
60GCE metadata requests."""
61
62GCE_METADATA_TIMEOUT = "GCE_METADATA_TIMEOUT"
63"""Environment variable defining the timeout in seconds to wait for the
64GCE metadata server when detecting the GCE environment.
65"""
66
67GCE_METADATA_DETECT_RETRIES = "GCE_METADATA_DETECT_RETRIES"
68"""Environment variable representing the number of retries that should be
69attempted on metadata lookup.
70"""
71
72NO_GCE_CHECK = "NO_GCE_CHECK"
73"""Environment variable controlling whether to check if running on GCE or not.
74
75The default value is false. Users have to explicitly set this value to true
76in order to disable the GCE check."""
77
78GCE_METADATA_MTLS_MODE = "GCE_METADATA_MTLS_MODE"
79"""Environment variable controlling the mTLS behavior for GCE metadata requests.
80
81Can be one of "strict", "none", or "default".
82"""
83
84GOOGLE_API_USE_CLIENT_CERTIFICATE = "GOOGLE_API_USE_CLIENT_CERTIFICATE"
85"""Environment variable controlling whether to use client certificate or not.
86
87The default value is false. Users have to explicitly set this value to true
88in order to use client certificate to establish a mutual TLS channel."""
89
90LEGACY_APPENGINE_RUNTIME = "APPENGINE_RUNTIME"
91"""Gen1 environment variable defining the App Engine Runtime.
92
93Used to distinguish between GAE gen1 and GAE gen2+.
94"""
95
96# AWS environment variables used with AWS workload identity pools to retrieve
97# AWS security credentials and the AWS region needed to create a serialized
98# signed requests to the AWS STS GetCalledIdentity API that can be exchanged
99# for a Google access tokens via the GCP STS endpoint.
100# When not available the AWS metadata server is used to retrieve these values.
101AWS_ACCESS_KEY_ID = "AWS_ACCESS_KEY_ID"
102AWS_SECRET_ACCESS_KEY = "AWS_SECRET_ACCESS_KEY"
103AWS_SESSION_TOKEN = "AWS_SESSION_TOKEN"
104AWS_REGION = "AWS_REGION"
105AWS_DEFAULT_REGION = "AWS_DEFAULT_REGION"
106
107
108GOOGLE_AUTH_TRUST_BOUNDARY_ENABLED = "GOOGLE_AUTH_TRUST_BOUNDARY_ENABLED"
109"""Environment variable controlling whether to enable trust boundary feature.
110
111.. deprecated::
112 This environment variable is deprecated and no longer has any effect.
113"""
114
115GOOGLE_API_CERTIFICATE_CONFIG = "GOOGLE_API_CERTIFICATE_CONFIG"
116"""Environment variable defining the location of Google API certificate config
117file."""
118
119CLOUDSDK_CONTEXT_AWARE_USE_CLIENT_CERTIFICATE = (
120 "CLOUDSDK_CONTEXT_AWARE_USE_CLIENT_CERTIFICATE"
121)
122"""Environment variable controlling whether to use client certificate or not.
123This variable is the fallback of GOOGLE_API_USE_CLIENT_CERTIFICATE."""
124
125CLOUDSDK_CONTEXT_AWARE_CERTIFICATE_CONFIG_FILE_PATH = (
126 "CLOUDSDK_CONTEXT_AWARE_CERTIFICATE_CONFIG_FILE_PATH"
127)
128"""Environment variable defining the location of Google API certificate config
129file. This variable is the fallback of GOOGLE_API_CERTIFICATE_CONFIG."""
130
131GOOGLE_API_PREVENT_AGENT_TOKEN_SHARING_FOR_GCP_SERVICES = (
132 "GOOGLE_API_PREVENT_AGENT_TOKEN_SHARING_FOR_GCP_SERVICES"
133)
134"""Environment variable to prevent agent token sharing for GCP services."""
135
136GOOGLE_API_USE_MTLS_ENDPOINT = "GOOGLE_API_USE_MTLS_ENDPOINT"
137"""Environment variable controlling whether to use mTLS endpoint or not."""