tree d43c66f38f316fdea6828701304aa7a4ef8c0143
parent 882d0ff28f71c6a22289a8345a24462665a05147
author bojeil-google <bojeil-google@users.noreply.github.com> 1613507600 -0800
committer GitHub <noreply@github.com> 1613507600 -0700
gpgsig -----BEGIN PGP SIGNATURE-----
 
 wsBcBAABCAAQBQJgLCwQCRBK7hj4Ov3rIwAAdHIIAHWLDhAe/ILkHHcXrZFDYrOk
 0FVzfnRZzzA9YfsZ4gyzOLnN+GU0W3+689h27H11gehEdTqTV5cb6ByVsqXdy8+k
 CgOr/lC6ev93GTaK+O7YErHpBbt6LCkPb1l92aIyBaFEoz36crE/Zn7DAtFMT6OG
 38AqdQFggwY+L7mSHd5XkJ5CDvph4Mfzwl/7ESVAltH5d9bcqxAgdhCJUIXGEtN4
 /+GwndcYaEAgGmcV7+AVJJ4kO/n9OWOpS54j96JXo9F7VHd43OVQ7HfNf9RPPGJf
 DI3+JOa9JJFF2IqJw2+5J9L3zWs6DUsYPUw6GBDMfKeX1OaSs6JM5CO9PUQLYaQ=
 =RAkn
 -----END PGP SIGNATURE-----
 

feat: workload identity federation support (#698)

Using workload identity federation, applications can access Google Cloud resources from Amazon Web Services (AWS), Microsoft Azure or any identity provider that supports OpenID Connect (OIDC). Workload identity federation is recommended for non-Google Cloud environments as it avoids the need to download, manage and store service account private keys locally.

This includes a rollforward of the [previous reverted PR](https://github.com/googleapis/google-auth-library-python/pull/686) and the [fix](https://github.com/googleapis/google-auth-library-python/pull/686) to not pass scopes to user credentials from `google.auth.default()`.