alloydb-auth-proxy
alloydb-auth-proxy copied to clipboard
Support SA key rotation
trafficstars
Related to https://github.com/GoogleCloudPlatform/cloud-sql-proxy/issues/205.
We generally recommend people use Workload Identity Federation to avoid long-lived SA keys, but in some cases, people have written infrastructure to rotate SA keys manually. This is a feature request to have the Proxy watch for credential changes and recreate its client when that happens.
Assuming we're OK with the license, this is the default library: https://github.com/fsnotify/fsnotify.
Given there's not much interest here, going to close this is unplanned.