Skip to main content

atmos.gcp

The atmos.gcp function runs atmos gcp through the current Atmos executable. Use it to generate short-lived Google Cloud credentials for GKE through Atmos Auth from automation.

Usage​

atmos.gcp(
*positionals,
flags = {},
args = [],
working_directory = ...,
env = ...,
output = "stream",
check = True,
)

Subcommands​

Pass the subcommand and any positional arguments as strings before the keyword arguments. The call atmos.gcp("gke", "token", flags = {"identity": "example-deployer"}) runs atmos gcp gke token --identity=example-deployer.

SubcommandPurpose
gke tokenGenerate a GKE bearer token as a Kubernetes ExecCredential.

See the atmos gcp gke reference and the atmos gcp command reference for details.

note

The gke token subcommand is normally invoked by kubectl from an Atmos-generated kubeconfig. Calling it from a script is useful when another tool needs the credential document. Capture the output and avoid printing it, because it contains a short-lived access token. The call requires a configured GCP identity and network access to Google Cloud.

Arguments​

*positionals

(Optional) Strings placed on the command line right after gcp, in order: the subcommand path and its positional arguments. For GKE credentials, pass "gke" and "token". Every value must be a string.

flags

(Optional) A dictionary of command-line options; see flag translation. The identity key becomes --identity (shorthand i ) and names the Atmos GCP identity to authenticate with. When it is omitted, Atmos selects the inherited or sole configured identity.

args
(Optional) A list or tuple of strings appended after the flags.
working_directory, env, output, check

(Optional) See atmos.run for process options and defaults.

Options other than the positionals are keyword-only.

Returns​

A result with stdout, stderr, and exit_code. See atmos.run for output and error behavior.

Examples​

Fetch a GKE credential​

credential = atmos.gcp("gke", "token", flags = {"identity": "example-deployer"}, output = "capture")
document = json.decode(credential.stdout)
print(document["kind"])

The command prints a Kubernetes ExecCredential document as JSON.

Use the inherited identity​

credential = atmos.gcp("gke", "token", output = "capture")