Skip to content

feat(bigquery): support authentication with ADC - #3348

Open
swarmia-eero wants to merge 1 commit into
evidence-dev:mainfrom
swarmia-eero:bigquery-adc
Open

swarmia-eero wants to merge 1 commit into
evidence-dev:mainfrom
swarmia-eero:bigquery-adc

Conversation

@swarmia-eero

Copy link
Copy Markdown

Summary

Service account keys should be treated as a last resort authentication method in GCP, due to the security risks related to long-living secrets living on disk: https://docs.cloud.google.com/docs/authentication#auth-decision-tree. ADC is most often the preferred method and comes with other upsides for BigQuery work:

  • User authentication in local development attributes queries to the actual user
  • ADC in CI allows using OIDC instead of issuing and storing service account keys

This adds ADC as an authentication method for self-hosting and local development. Studio is unchanged.

Smoke-tested locally with a stub project and ADC authentication.

Comment on lines +73 to +93
### Application Default Credentials (CLI and self-hosted)

When running the CLI or a self-hosted `evidence serve`, you can skip the key file and use [Application Default Credentials](https://cloud.google.com/docs/authentication/application-default-credentials) instead:

```yaml
type: bigquery
project: my-gcp-project
adc: true
datasets:
- analytics
```

Evidence then authenticates with, in order:

1. The key file at `GOOGLE_APPLICATION_CREDENTIALS`.
2. Your own login from `gcloud auth application-default login`.
3. The attached service account when running on GCP (Cloud Run, GCE, GKE).

The identity needs the same **BigQuery Job User** and **BigQuery Data Viewer** roles described above.


Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very open to feedback regarding how the docs should discuss this, especially given that ADC is not supported on the Studio side.

@vercel

vercel Bot commented Oct 6, 2026

Copy link
Copy Markdown

@swarmia-eero is attempting to deploy a commit to the Evidence Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant