镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

feat(auth): wire gRPC mTLS cert rotation into secure_authorized_channel - #18557

Open
agrawalradhika-cell wants to merge 4 commits into
googleapis:mainfrom
agrawalradhika-cell:feat/grpc-cert-rotation-channel
Open

agrawalradhika-cell wants to merge 4 commits into
googleapis:mainfrom
agrawalradhika-cell:feat/grpc-cert-rotation-channel

Conversation

@agrawalradhika-cell

@agrawalradhika-cell agrawalradhika-cell commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Part 2 of 2 splitting #18019.
Stacked on top of #18556.

This PR wires CertRotationInterceptor and MTLSRefreshingChannel into google.auth.transport.grpc.secure_authorized_channel when an mTLS client certificate is configured, and updates google.auth.transport._mtls_helper.call_client_cert_callback to decrypt passphrase-protected private keys before returning (cert_bytes, key_bytes).

See go/grpc-cert-rotation-in-pythonsdk-for-x509 for details.

  • Make sure to open an issue as a bug/issue before writing your code! That way we can discuss the change, evaluate designs, and agree on the general idea - b/497848161
  • Ensure the tests and linter pass
  • Code coverage does not decrease (if any source code was changed)
  • Appropriate docs were updated (if necessary)

Pre-review checklist

  • Split from Part 2 of 2 splitting feat: [grpc] Add retry logic when certificate mismatch for existing credentials & Agent Identity workloads  #18019.
  • Self-reviewed the full diff line by line (go/author-standard).
  • [] Tested manually / end-to-end against a real environment.
    • Test script and output:
  • Added or updated unit tests covering happy paths and error cases.
  • [] Checked shared code paths for regressions and backwards compatibility.
    • Adjacent features verified:
  • [] Checked parity across sibling flows (other transports, credential types, or sync/async counterparts).
    • Out of scope flows and tracking bugs (b/):

… gRPC mTLS

Signed-off-by: Radhika Agrawal <agrawalradhika@google.com>
Signed-off-by: Radhika Agrawal <agrawalradhika@google.com>
@agrawalradhika-cell
agrawalradhika-cell requested review from a team as code owners October 2, 2026 21:31

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces automatic mTLS certificate rotation and channel refreshing for gRPC transports. It adds a new mtls_interceptor.py module containing CertRotationInterceptor and MTLSRefreshingChannel to intercept and retry failed calls on UNAUTHENTICATED errors, and updates _mtls_helper.py to decrypt passphrase-protected private keys. Feedback on these changes suggests ensuring that registered done callbacks are triggered when refresh_logic fails to prevent downstream callers from hanging, and fully implementing the grpc.Call interface in _DeadlineExceededError to avoid potential AttributeError exceptions.

Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py
Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant