Interface Compute.AdditionalRegistry.Authenticator.GcpWorkloadIdentityFederationOrBuilder

All Superinterfaces:
com.google.protobuf.MessageLiteOrBuilder, com.google.protobuf.MessageOrBuilder
All Known Implementing Classes:
Compute.AdditionalRegistry.Authenticator.GcpWorkloadIdentityFederation, Compute.AdditionalRegistry.Authenticator.GcpWorkloadIdentityFederation.Builder
Enclosing class:
Compute.AdditionalRegistry.Authenticator

public static interface Compute.AdditionalRegistry.Authenticator.GcpWorkloadIdentityFederationOrBuilder extends com.google.protobuf.MessageOrBuilder
  • Method Summary

    Modifier and Type
    Method
    Description
    Required.
    com.google.protobuf.ByteString
    Required.
    Optional.
    com.google.protobuf.ByteString
    Optional.
    Optional.
    com.google.protobuf.ByteString
    Optional.

    Methods inherited from interface com.google.protobuf.MessageLiteOrBuilder

    isInitialized

    Methods inherited from interface com.google.protobuf.MessageOrBuilder

    findInitializationErrors, getAllFields, getDefaultInstanceForType, getDescriptorForType, getField, getInitializationErrorString, getOneofFieldDescriptor, getRepeatedField, getRepeatedFieldCount, getUnknownFields, hasField, hasOneof
  • Method Details

    • getAudience

      String getAudience()
       Required. Full resource name of the GCP Workload Identity Provider, used
       as the Security Token Service (STS) token-exchange audience. E.g.
       "//iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL_ID/providers/PROVIDER_ID".
       The provider must be configured to trust the issuer
       `https://federation.namespaceapis.com`.
       
      string audience = 1;
      Returns:
      The audience.
    • getAudienceBytes

      com.google.protobuf.ByteString getAudienceBytes()
       Required. Full resource name of the GCP Workload Identity Provider, used
       as the Security Token Service (STS) token-exchange audience. E.g.
       "//iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL_ID/providers/PROVIDER_ID".
       The provider must be configured to trust the issuer
       `https://federation.namespaceapis.com`.
       
      string audience = 1;
      Returns:
      The bytes for audience.
    • getServiceAccountEmail

      String getServiceAccountEmail()
       Optional. Email of the service account to impersonate after federation
       (e.g. "name@project.iam.gserviceaccount.com"). If set, the federated
       identity must hold `roles/iam.workloadIdentityUser` on this service
       account, and the service account must hold `roles/artifactregistry.reader`.
       If empty, the federated identity accesses the registry directly and must
       itself hold `roles/artifactregistry.reader`.
       
      string service_account_email = 2;
      Returns:
      The serviceAccountEmail.
    • getServiceAccountEmailBytes

      com.google.protobuf.ByteString getServiceAccountEmailBytes()
       Optional. Email of the service account to impersonate after federation
       (e.g. "name@project.iam.gserviceaccount.com"). If set, the federated
       identity must hold `roles/iam.workloadIdentityUser` on this service
       account, and the service account must hold `roles/artifactregistry.reader`.
       If empty, the federated identity accesses the registry directly and must
       itself hold `roles/artifactregistry.reader`.
       
      string service_account_email = 2;
      Returns:
      The bytes for serviceAccountEmail.
    • getUsername

      String getUsername()
       Optional. The username to use for the registry authentication. Defaults
       to "oauth2accesstoken".
       
      string username = 3;
      Returns:
      The username.
    • getUsernameBytes

      com.google.protobuf.ByteString getUsernameBytes()
       Optional. The username to use for the registry authentication. Defaults
       to "oauth2accesstoken".
       
      string username = 3;
      Returns:
      The bytes for username.