Skip to content

feat(auth): add CertRotationInterceptor and MTLSRefreshingChannel for gRPC mTLS - #18556

Open
agrawalradhika-cell wants to merge 11 commits into
googleapis:mainfrom
agrawalradhika-cell:feat/grpc-mtls-interceptor
Open

agrawalradhika-cell wants to merge 11 commits into
googleapis:mainfrom
agrawalradhika-cell:feat/grpc-mtls-interceptor

Conversation

@agrawalradhika-cell

@agrawalradhika-cell agrawalradhika-cell commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Part 1 of 2 splitting #18019.

This PR adds the standalone google.auth.transport.mtls_interceptor module (CertRotationInterceptor and MTLSRefreshingChannel) and its unit tests (tests/transport/test_mtls_interceptor.py) to support automatic gRPC mTLS certificate rotation upon UNAUTHENTICATED errors when client certificates rotate.

See go/grpc-cert-rotation-in-pythonsdk-for-x509 for details.

  • Make sure to open an issue as a bug/issue before writing your code! That way we can discuss the change, evaluate designs, and agree on the general idea - b/497848161
  • Ensure the tests and linter pass
  • Code coverage does not decrease (if any source code was changed)
  • Appropriate docs were updated (if necessary)

Pre-review checklist

  • Split from Part 1 of 2 splitting feat: [grpc] Add retry logic when certificate mismatch for existing credentials & Agent Identity workloads  #18019.
  • Self-reviewed the full diff line by line (go/author-standard).
  • Tested manually / end-to-end against a real environment.
    • Test script and output:
  • Added or updated unit tests covering happy paths and error cases.
  • Checked shared code paths for regressions and backwards compatibility.
    • Adjacent features verified: This change doesn't impact any files, this is just a helper
  • Checked parity across sibling flows (credential types)
  • Out of scope flows and tracking bugs - grpc async

… gRPC mTLS

Signed-off-by: Radhika Agrawal <agrawalradhika@google.com>

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces an mTLS interceptor and channel wrapper (mtls_interceptor.py) along with comprehensive unit tests to handle automatic certificate rotation and retry logic for gRPC client calls. The review feedback suggests several improvements, including removing defensive getattr checks for guaranteed attributes, logging swallowed exceptions in callback execution blocks to aid in debugging, and implementing missing standard grpc.Call methods in _DeadlineExceededError to prevent potential AttributeError crashes in downstream code.

Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py
Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py
Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py
Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py
Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py
Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py Outdated
Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py Outdated
Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py Outdated
Comment thread packages/google-auth/google/auth/transport/mtls_interceptor.py
agrawalradhika-cell and others added 10 commits October 5, 2026 11:14
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Added methods for initial and trailing metadata, time remaining, and active status
Handle exceptions during channel subscription to avoid crashes.
Removed redundant pass statements in exception handling.
Added logic to fire callbacks after handling exceptions.
…Error

Add cancel and add_callback methods to interceptor to avoid AttributeError

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant