Skip to content

Introduces a more strict is_gce() check - #5536

Draft
IvanBM18 wants to merge 3 commits into
fix/is-gce-skip-swarmingfrom
fix/strict-is-gce
Draft

IvanBM18 wants to merge 3 commits into
fix/is-gce-skip-swarmingfrom
fix/strict-is-gce

Conversation

@IvanBM18

@IvanBM18 IvanBM18 commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Recent changes made it so we can know overide the gce metadata host, which helps when we want to add a fake server in its place, but this broke CF running on swarming bos, because there we have a server that mint's tokens, which fools CF to believe that it is in gce, when is not.

So now we introduce a more strict is_gce() check that only true metadata servers can answer.

More info in #5535

Tests

  • Creates some Tests inside
  • Currently being tested on dev

…ta emulators

LUCI's local auth server (exported via GCE_METADATA_HOST by luci-auth
context on Swarming) only serves tokens and a few project/instance
values. Since #5479, is_gce() honours GCE_METADATA_HOST and only checks
for a TCP connection, so Swarming bots were treated as GCE and crashed
fetching instance/zone (404).

Probe instance/id instead, which real GCE and the test emulator serve
but LUCI's emulator does not.

Bug: b/571127789
@IvanBM18
IvanBM18 added this pull request to stack #5537 October 7, 2026 23:50

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant