Find integrations that need a run-as service account

This page is part of Prepare for upcoming authorization changes. It helps you find the integrations that need a run-as service account before the changes take effect.

Determine whether an integration needs one

You only need a run-as service account when nobody's credentials are available for the whole run. That happens in two situations, and only two:

How the integration runs Are someone's credentials available? Needs a run-as service account?
Synchronously — someone starts it and waits for the result Yes, for the whole run No
Asynchronously — it's queued and finishes later Only at the moment it's triggered Yes
Unattended — a schedule or an event starts it No, there's never a person Yes

Identify affected integrations

First, does it ever run without a person? It does if any of these are true:

Second, is its run-as service account empty? To list every published version in a region alongside its run-as service account, run the following command:

curl -s -G -H "Authorization: Bearer $(gcloud auth print-access-token)" \
  --data-urlencode "filter=state=ACTIVE" \
  --data-urlencode "pageSize=1000" \
  "https://REGION-integrations.googleapis.com/v1/projects/PROJECT_ID/locations/REGION/integrations/-/versions" \
| jq -r '.integrationVersions[]
         | [ .name, (.runAsServiceAccount // "NONE") ]
         | @tsv'

Replace the following:

  • REGION: the region of your integration. For the list of supported regions, see Locations.
  • PROJECT_ID: the ID of your Google Cloud project
  • A row showing NONE needs action only if the first half applies to it too.
  • To check a single integration instead, open it in the integration editor and click (Integration settings) in the editor toolbar. The Service account field shows the run-as service account, and is empty if the integration doesn't have one.

What's next