Skip to content

fix(providers): refresh GCP metadata server token on expiration - #8929

Merged
DOsinga merged 1 commit into
aaif-goose:mainfrom
froody:gcp-auth
May 13, 2026
Merged

fix(providers): refresh GCP metadata server token on expiration#8929
DOsinga merged 1 commit into
aaif-goose:mainfrom
froody:gcp-auth

Conversation

@froody

@froody froody commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

The GCP metadata server provides a token that expires, but the original implementation of DefaultAccount in GcpAuth was caching the response of the metadata server directly in the credentials structure instead of fetching a new token when needed. This effectively created an infinite-lived default credential until Goose restarted, at which point it'd read the metadata server again. I have modified AdcCredentials::DefaultAccount to store the base URL instead of the one-time token, and get_default_access_token to actually re-fetch the token using the URL so the standard caching mechanism works properly and automatically refreshes it on expiration.

Summary

Testing

Related Issues

Relates to #ISSUE_ID
Discussion: LINK (if any)

Screenshots/Demos (for UX changes)

Before:

After:

The GCP metadata server provides a token that expires, but the original implementation of DefaultAccount in GcpAuth was caching the response of the metadata server directly in the credentials structure instead of fetching a new token when needed. This effectively created an infinite-lived default credential until Goose restarted, at which point it'd read the metadata server again. I have modified AdcCredentials::DefaultAccount to store the base URL instead of the one-time token, and get_default_access_token to actually re-fetch the token using the URL so the standard caching mechanism works properly and automatically refreshes it on expiration.

Signed-off-by: Tom Birch <tom@neara.com>

@jessburnett jessburnett left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great @froody. Thank you for your contribution

@DOsinga
DOsinga added this pull request to the merge queue May 13, 2026
Merged via the queue into aaif-goose:main with commit 81c59e0 May 13, 2026
21 checks passed
lifeizhou-ap added a commit that referenced this pull request May 14, 2026
* main: (66 commits)
  Switch GH pages deploy to actions/artifact workflow (#9025)
  fix(summon): re-apply canonical limits when delegate overrides model (#9183)
  Split code signing from build (#8587)
  refactor(logging): consolidate logging setup into shared helper in goose crate (#8817)
  fix(cli): report cumulative total_tokens in stream-json/json output (#8910)
  plugins: add open plugins (just skills for now) (#9063)
  fix(providers): refresh GCP metadata server token on expiration (#8929)
  chore(deps): bump the cargo-minor-and-patch group across 1 directory with 14 updates (#9178)
  chore(deps): bump bzip2 from 0.5.2 to 0.6.1 (#8964)
  chore(deps): bump tauri from 2.10.3 to 2.11.1 in /ui/goose2/src-tauri (#9066)
  chore(deps): bump hono from 4.12.14 to 4.12.18 in /evals/open-model-gym/mcp-harness (#9073)
  localize hardcoded strings in provider settings UI (#8931)
  chore(deps): bump @babel/plugin-transform-modules-systemjs from 7.28.5 to 7.29.4 in /documentation (#9122)
  move settings into app shell (#9047)
  Add Location column to CLI skills table (#8785)
  (feat): add routstr as a declarative provider (#9175)
  Add FuturMix provider (#8840)
  fix: convert quoted numeric config values to numbers if needed (#8844)
  fix(ui): keep SSE reconnect loop alive on long disconnects (#8717) (#8846)
  fix(openai): apply request_params to outgoing API payload (#9151)
  ...
shafqatevo pushed a commit to shafqatevo/goose that referenced this pull request Aug 7, 2026
…-goose#8929)

Signed-off-by: Tom Birch <tom@neara.com>
Co-authored-by: Tom Birch <tom@neara.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants