Repository navigation
fix(bigtable): fix authentication scopes for metrics exporter - #18609
Conversation
There was a problem hiding this comment.
Code Review
This pull request introduces credential re-scoping for the Cloud Monitoring metrics exporter to prevent authentication failures when using credentials pinned to Bigtable-only scopes. It also adds a mechanism to disable the exporter after encountering non-retryable authentication or authorization errors, along with comprehensive unit tests. The review feedback highlights three key improvement opportunities: using 'getattr' to safely access the 'scopes' attribute on 'Scoped' credentials to avoid potential 'AttributeError's, handling credentials passed as positional arguments in 'client_args', and returning 'MetricExportResult.SUCCESS' instead of 'FAILURE' when the exporter is disabled to completely silence OpenTelemetry SDK warning logs.
The Bigtable client holds an inner Metrics client, for exporting client-side metrics. This inner-client shares credentials with the Bigtable client. If the Bigtable client is created with scopes that don't allow interacting with the metrics service, the metrics client will fail on each write, printing logs each time
This PR addresses the issue by: