gcp

package module
v0.0.0-...-16b5795 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 10, 2026 License: OSL-3.0 Imports: 29 Imported by: 0

Documentation

Overview

Package gcp provides helpers for classifying GCP API errors.

Package gcp provides Google Cloud Platform provider implementation

Package gcp provides GCP recommendations client

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func IsPermissionError

func IsPermissionError(err error) bool

IsPermissionError reports whether err represents a GCP permission / authorization failure — typically a missing IAM role on the deploy service account. The GCP collector uses this to downgrade per-account log severity from ERROR to WARN: the operator can fix the gap by granting the missing role, so it is not a genuine collector error and should not drown out other signals in the log stream.

It returns true for:

  • *googleapi.Error with Code == 403 (REST surface, e.g. compute REST client returns "googleapi: Error 403: Required '...' permission")
  • gRPC status with codes.PermissionDenied (gRPC surface, e.g. when a client uses the gRPC transport rather than REST)

Wrapped errors (via fmt.Errorf("...: %w", err)) are unwrapped so the scheduler's wrap-and-rethrow chain still classifies correctly.

Returns false for nil and for any other error.

Types

type ProjectsClient

type ProjectsClient interface {
	GetProject(ctx context.Context, req *resourcemanagerpb.GetProjectRequest) (*resourcemanagerpb.Project, error)
	Close() error
}

ProjectsClient interface for project operations (enables mocking).

type Provider

type Provider struct {
	// contains filtered or unexported fields
}

Provider implements the provider.Provider interface for Google Cloud Platform.

func NewProvider

func NewProvider(config *provider.ProviderConfig) (*Provider, error)

NewProvider creates a new GCP provider.

Project resolution order:

  1. config.GCPProjectID (typed field, preferred)
  2. config.Profile (deprecated overload — kept for backwards compatibility)
  3. Application Default Credentials' default project

Credential resolution: if config.GCPTokenSource is a non-nil oauth2.TokenSource, it is installed via option.WithTokenSource so all downstream clients use those credentials. Otherwise, clients fall back to Application Default Credentials.

func NewProviderWithCredentials

func NewProviderWithCredentials(ctx context.Context, projectID string, ts oauth2.TokenSource) *Provider

NewProviderWithCredentials creates a GCP provider that uses the supplied token source instead of Application Default Credentials. Use this for service account key or workload identity federation modes.

func NewProviderWithProject

func NewProviderWithProject(ctx context.Context, projectID string, opts ...option.ClientOption) *Provider

NewProviderWithProject creates a new GCP provider with a specific project.

func (*Provider) DisplayName

func (p *Provider) DisplayName() string

DisplayName returns the provider display name.

func (*Provider) GetAccounts

func (p *Provider) GetAccounts(ctx context.Context) ([]common.Account, error)

GetAccounts returns all accessible GCP projects.

func (*Provider) GetCredentials

func (p *Provider) GetCredentials() (provider.Credentials, error)

GetCredentials returns the current GCP credentials information.

This is credential *introspection* (which source is in use), not *validation* (do the credentials work). It deliberately performs NO network call: the source is determined from local inspection only. To verify the credentials actually work, call ValidateCredentials, which issues the GetProject RPC.

func (*Provider) GetDefaultRegion

func (p *Provider) GetDefaultRegion() string

GetDefaultRegion returns the default GCP region.

func (*Provider) GetRecommendationsClient

func (p *Provider) GetRecommendationsClient(ctx context.Context) (provider.RecommendationsClient, error)

GetRecommendationsClient creates a recommendations client.

func (*Provider) GetRegions

func (p *Provider) GetRegions(ctx context.Context) ([]common.Region, error)

GetRegions returns all available GCP regions using Compute Engine API.

func (*Provider) GetServiceClient

func (p *Provider) GetServiceClient(ctx context.Context, service common.ServiceType, region string) (provider.ServiceClient, error)

GetServiceClient creates a service client for the specified service and region.

func (*Provider) GetSupportedServices

func (p *Provider) GetSupportedServices() []common.ServiceType

GetSupportedServices returns the GCP services that have commitment recommendations. Cloud Storage is excluded: it has no commitment product.

func (*Provider) IsConfigured

func (p *Provider) IsConfigured() bool

IsConfigured checks if GCP credentials are configured.

When a client has been injected via SetProjectsClient (test path), the injector owns its lifecycle and we must NOT Close() it here — otherwise subsequent calls in the same test hit a closed connection. In production the client is constructed internally and we retain Close responsibility.

func (*Provider) Name

func (p *Provider) Name() string

Name returns the provider name.

func (*Provider) SetProjectsClient

func (p *Provider) SetProjectsClient(client ProjectsClient)

SetProjectsClient sets the projects client (for testing).

func (*Provider) SetRegionsClient

func (p *Provider) SetRegionsClient(client RegionsClient)

SetRegionsClient sets the regions client (for testing).

func (*Provider) SetResourceManagerService

func (p *Provider) SetResourceManagerService(svc ResourceManagerService)

SetResourceManagerService sets the resource manager service (for testing).

func (*Provider) ValidateCredentials

func (p *Provider) ValidateCredentials(ctx context.Context) error

ValidateCredentials validates that GCP credentials are valid. Same injected-client ownership rule as IsConfigured — see that godoc.

type RecommendationsClientAdapter

type RecommendationsClientAdapter struct {
	// contains filtered or unexported fields
}

RecommendationsClientAdapter aggregates GCP CUD and commitment recommendations across all services.

func (*RecommendationsClientAdapter) GetAllRecommendations

func (r *RecommendationsClientAdapter) GetAllRecommendations(ctx context.Context) ([]common.Recommendation, error)

GetAllRecommendations retrieves all GCP commitment recommendations across all services.

func (*RecommendationsClientAdapter) GetRecommendations

GetRecommendations retrieves all GCP commitment recommendations across all services and regions.

Two-level concurrent fan-out:

  • Outer: errgroup over regions, capped at gcpRegionConcurrency() (CUDLY_GCP_REGION_PARALLELISM, default 10) to stay polite to the project-scoped Recommender API quota.
  • Inner: within each region's goroutine, the three service calls (compute, cloud-sql, memorystore) run as concurrent goroutines under a per-region sub-errgroup, so the per-region cost is max(service latencies) rather than their sum.

Behavior change vs the previous nested for-loops: per-(region, service) errors that were previously silently swallowed (`if err == nil { ... }` shape) are now logged at WARN with region+service identifiers so misconfigured projects are diagnosable. Errors do NOT cancel siblings — each goroutine returns nil to its errgroup, matching the previous silent-skip-on-err semantics.

After the outer Wait(), ctx.Err() is checked and propagated so a canceled parent ctx surfaces as context.Canceled / context.DeadlineExceeded rather than being swallowed by the per-region error-isolation goroutines.

Mirrors the Azure parallelisation in providers/azure/recommendations.go (closes #258, commit b10326c5) and the AWS service-loop parallelisation (closes #266).

func (*RecommendationsClientAdapter) GetRecommendationsForService

func (r *RecommendationsClientAdapter) GetRecommendationsForService(ctx context.Context, service common.ServiceType) ([]common.Recommendation, error)

GetRecommendationsForService retrieves GCP commitment recommendations for a specific service.

type RegionsClient

type RegionsClient interface {
	List(ctx context.Context, req *computepb.ListRegionsRequest) RegionsIterator
	Close() error
}

RegionsClient interface for regions operations (enables mocking).

type RegionsIterator

type RegionsIterator interface {
	Next() (*computepb.Region, error)
}

RegionsIterator interface for regions iteration (enables mocking).

type ResourceManagerService

type ResourceManagerService interface {
	ListProjects(ctx context.Context) ([]*cloudresourcemanager.Project, error)
}

ResourceManagerService interface for resource manager operations (enables mocking).

Directories

Path Synopsis
internal
billingcurrency
Package billingcurrency checks the currency of Cloud Billing Catalog prices.
Package billingcurrency checks the currency of Cloud Billing Catalog prices.
skumatch
Package skumatch holds the matching rules the GCP services share when they pick a price out of Cloud Billing catalog SKUs.
Package skumatch holds the matching rules the GCP services share when they pick a price out of Cloud Billing catalog SKUs.
services
cloudsql
Package cloudsql provides GCP Cloud SQL commitments client
Package cloudsql provides GCP Cloud SQL commitments client
cloudstorage
Package cloudstorage provides GCP Cloud Storage commitments client
Package cloudstorage provides GCP Cloud Storage commitments client
computeengine
Package computeengine provides GCP Compute Engine Committed Use Discounts client
Package computeengine provides GCP Compute Engine Committed Use Discounts client
memorystore
Package memorystore provides GCP Memorystore (Redis) commitments client
Package memorystore provides GCP Memorystore (Redis) commitments client

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL