Skip to content

Google Cloud SDK OAuth setup

Configure Google Cloud SDK OAuth so gcloud inside the sandbox can use the logged-in user credential.

Note: mikan stores the Google authorized_user JSON in the vault and saves target path metadata. The image sandbox automatically projects this vault file into the container target path; existing container / firecracker runtimes still do not automatically project files.

In Google Cloud Console, go to:

APIs & Services → Credentials → Create Credentials → OAuth client ID

Configure:

  • Application type: Web application
  • Authorized redirect URI: <LINK_URL>/oauth/callback

Example:

LINK_URL=https://mikan.example.com
Redirect URI=https://mikan.example.com/oauth/callback

If the OAuth app is still in testing mode, add users at:

OAuth consent screen → Test users
Terminal window
export LINK_URL="https://mikan.example.com"
export GOOGLE_CLOUD_SDK_CLIENT_ID="<client-id>"
export GOOGLE_CLOUD_SDK_CLIENT_SECRET="<client-secret>"

If LINK_PORT is not set, mikan listens on 8181 by default when LINK_URL exists.

Optional: override default scopes:

Terminal window
export GOOGLE_CLOUD_SDK_OAUTH_SCOPES="openid https://www.googleapis.com/auth/userinfo.email https://www.googleapis.com/auth/cloud-platform"

If you want later runtime executions to automatically project the credential file to /root/.config/gcloud/application_default_credentials.json, start mikan with the image sandbox:

Terminal window
mikan --sandbox=image:mikan-sandbox:tools /path/to/workspace

In a DM with the bot, type:

/pi-login

Open the link returned by mikan and choose Google Cloud SDK (gcloud).

After success, mikan:

  • stores vault file: gcloud-adc.json
  • projects it in the sandbox to: /root/.config/gcloud/application_default_credentials.json
  • sets env:
    • GOOGLE_APPLICATION_CREDENTIALS=/root/.config/gcloud/application_default_credentials.json
    • CLOUDSDK_AUTH_CREDENTIAL_FILE_OVERRIDE=/root/.config/gcloud/application_default_credentials.json

CLOUDSDK_AUTH_CREDENTIAL_FILE_OVERRIDE makes gcloud prefer this credential file.

  • mikan uses a web OAuth callback, so the Google OAuth client must be Web application, not a desktop app.
  • If Google does not return a refresh_token, revoke the existing consent and run /pi-login again. mikan requests access_type=offline and prompt=consent, but Google may still omit the refresh token because of existing authorization.
  • To make the credential file appear automatically at /root/.config/gcloud/application_default_credentials.json, use the image sandbox. container / firecracker currently only save file credential metadata and do not project it automatically.