Skip to content

add gcp_audience input and pass it to the auth action warn when gcp_audience is set without a workload identity provider - #536

Open
rootkiller6788 wants to merge 2 commits into
google-github-actions:mainfrom
rootkiller6788:feat-wif-audience-input
Open

rootkiller6788 wants to merge 2 commits into
google-github-actions:mainfrom
rootkiller6788:feat-wif-audience-input

Conversation

@rootkiller6788

Copy link
Copy Markdown

Fixes #484.

Adds a gcp_audience input and passes it through to the auth action's audience input, which is what ends up in the OIDC token we hand to Workload Identity Federation. Right now we always request the provider resource name, so a provider configured to expect something else can't be used with this action at all.

Leaving the input unset keeps today's behaviour: the auth action falls back to the workload identity provider when the value is empty, so this is purely opt-in.

I also added a check in the existing input validation step for the case where someone sets gcp_audience without gcp_workload_identity_provider - it would silently do nothing otherwise, which is a confusing way to find out.

Tested the validation script locally against a few input combinations (WIF + audience, audience without WIF, neither, no auth, three auth methods at once) and the existing warnings and the step's exit code are unchanged. I did not regenerate the README input table with npm run docs - say the word if you want that in this PR.

WIF setups that pin a custom audience on the provider currently can't work
here, because we request the default audience (the provider resource name)
when minting the OIDC token while the provider expects something else.

The auth action already has an 'audience' input for this, so this just
surfaces it. Leaving it unset keeps the old behaviour: auth falls back to
the workload identity provider when the value is empty.
It's easy to drop 'gcp_audience' into a workflow that authenticates with an
API key and then wonder why nothing changed - the audience only ends up in
the OIDC token, so without WIF there is nothing to apply it to. Added it to
the existing input checks next to the other WIF-specific ones.
@rootkiller6788
rootkiller6788 marked this pull request as ready for review October 5, 2026 06:09
@rootkiller6788
rootkiller6788 requested review from a team as code owners October 5, 2026 06:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

Audience should be exposed when using WIF

1 participant