fleet-memory/hindsight-api/hindsight_api
Chris Bartholomew d2504ac5ed
Fix GCS auth for Workload Identity Federation credentials (#518)
* Fix GCS auth for external_account credentials (Workload Identity)

obstore's built-in credential parsing only supports service_account and
authorized_user JSON types. Use google.auth as a credential_provider
callback to support all credential types including external_account
(Workload Identity Federation), impersonated credentials, and metadata
server credentials.

* Hide GOOGLE_APPLICATION_CREDENTIALS during GCSStore construction

GCSStore eagerly parses the credential file from env vars even when a
custom credential_provider is passed. Temporarily unset the env var
during construction so obstore doesn't choke on external_account
credential files (Workload Identity Federation).

* Support HINDSIGHT_GOOGLE_CREDENTIALS_FILE for GCS auth

When GOOGLE_APPLICATION_CREDENTIALS must be unset to prevent obstore
from parsing unsupported credential types (e.g. external_account),
google.auth can load credentials from HINDSIGHT_GOOGLE_CREDENTIALS_FILE
instead. This avoids mutating env vars at runtime.

* Simplify GCS credential workaround: hide env var during construction

Remove HINDSIGHT_GOOGLE_CREDENTIALS_FILE indirection. Instead, let
google.auth.default() load credentials normally via GOOGLE_APPLICATION_CREDENTIALS,
then temporarily hide the env var during GCSStore() construction so obstore
doesn't try to parse credential types it doesn't support.

* Work around obstore bug: hide env var during GCSStore construction

obstore always parses credential files from GOOGLE_APPLICATION_CREDENTIALS
and the well-known ADC path, even when credential_provider is supplied
(contrary to docs). This crashes on external_account credentials from
Workload Identity Federation.

Temporarily hide the env var during GCSStore() construction. google.auth
has already loaded credentials by this point via credential_provider.
2026-03-07 08:59:51 +01:00
..
admin feat: new 'worker' service (#176) 2026-01-20 10:17:56 +01:00
alembic feat: mental model history tracking and UI diff view (#516) 2026-03-06 17:50:48 +01:00
api feat: mental model history tracking and UI diff view (#516) 2026-03-06 17:50:48 +01:00
engine Fix GCS auth for Workload Identity Federation credentials (#518) 2026-03-07 08:59:51 +01:00
extensions Add on_file_convert_complete extension hook after file-to-markdown conversion (#507) 2026-03-06 09:56:53 +01:00
webhooks fix: use correct schema name in webhook outbox callback to prevent silent transaction rollback (#499) 2026-03-05 17:07:48 +01:00
worker feat: webhook system with retain.completed event, UI, and docs (#487) 2026-03-04 14:17:01 +01:00
__init__.py Release v0.4.16 2026-03-05 17:54:59 +01:00
banner.py feat: support for pgvectorscale (DiskANN) (#378) 2026-02-16 14:19:56 +01:00
config.py feat: mental model history tracking and UI diff view (#516) 2026-03-06 17:50:48 +01:00
config_resolver.py Fix bank config API for multi-tenant schema isolation (#417) 2026-02-20 23:43:52 +01:00
daemon.py feat: improve openclaw and hindisght-embed params (#279) 2026-02-03 09:39:04 +01:00
main.py feat: mental model history tracking and UI diff view (#516) 2026-03-06 17:50:48 +01:00
mcp_local.py fix(mcp): unify hindsight-mcp-local and server mcp (#407) 2026-02-19 17:57:17 +01:00
mcp_tools.py Fix bank-level MCP tool filtering for FastMCP 3.x (#491) 2026-03-04 10:29:29 -05:00
metrics.py chore: remove dead code (#245) 2026-01-30 09:16:32 +01:00
migrations.py fix(performance): improve recall and retain performance on large banks (#469) 2026-03-03 13:35:22 +01:00
models.py Add bank-scoped validation to engine and HTTP handlers (#454) 2026-03-02 09:55:21 +01:00
pg0.py feat: support vertex as llm provider (#233) 2026-01-29 16:13:57 -05:00
server.py Fix: Load extensions in server.py for multi-worker deployments (#155) 2026-01-13 17:55:33 +01:00
tracing.py feat: add otel traceability (#330) 2026-02-10 12:20:48 +01:00
utils.py fix(helm): improve appVersion usage (#326) 2026-02-09 11:35:08 +01:00