Authentication (gh auth)#
pw_ghish: GitHub CLI-like interface for Gerrit code reviews and CI checks
./gh auth checks authentication status across the three backends used by
pw_ghish:
Gerrit Code Review (e.g.,
pigweed-review.googlesource.com)LUCI Buildbucket & LogDog (
cr-buildbucket.appspot.com,logs.chromium.org)Google Issue Tracker / Buganizer (
issuetracker.corp.googleapis.comorissuetracker.googleapis.com)
Command reference#
Command |
Description |
|---|---|
|
Check authentication status across Gerrit, LUCI Buildbucket, and
Buganizer. Exits |
|
Output JSON authentication status (fields: |
Checking authentication status#
Run ./gh auth status to verify your credentials:
$ ./gh auth status
Authentication Mode: googler (auto-detected (gob-curl on PATH))
pigweed-review.googlesource.com (Gerrit)
✓ Logged in to pigweed-review.googlesource.com as Keir Mierle <keir@google.com> (account #1000020)
- Method: gob-curl
cr-buildbucket.appspot.com (LUCI Buildbucket & LogDog)
✓ Authenticated with cr-buildbucket.appspot.com via luci-auth (internal & public builders visible)
- Method: luci-auth
issuetracker.corp.googleapis.com (Google Issue Tracker)
✓ Authenticated with issuetracker.corp.googleapis.com via sso_client + luci-auth (quota project: pigweed-gce)
- Method: sso_client + luci-auth
- Quota project: pigweed-gce
Pass --json to output specific fields for scripts or tools:
$ ./gh auth status --json mode,authenticated,gerrit,luci
Authentication modes#
pw_ghish supports four authentication modes via --auth-mode or
GH_ISH_AUTH_MODE:
Mode |
Behavior |
|---|---|
|
(Default) Selects |
|
Requires authenticated access to both Gerrit and LUCI Buildbucket so
internal tryjob buckets (such as |
|
Authenticates Gerrit via |
|
Uses unauthenticated HTTP requests for all services. |
Configuration precedence#
The active authentication mode is resolved in the following order:
CLI flag:
--auth-mode <auto|googler|community|none>Environment variable:
GH_ISH_AUTH_MODE=<auto|googler|community|none>Git configuration:
git config ghish.authmode <auto|googler|community|none>Default:
auto
Credential resolution#
Gerrit Code Review#
When GH_ISH_AUTH_METHOD is auto (the default), pw_ghish looks up
Gerrit credentials in the following order:
GERRIT_TOKENenvironment variable (HTTP Bearer or Basic token).gob-curlonPATH.Git cookie file from
git config http.cookiefileor~/.gitcookies.Machine credentials in
~/.netrcor~/_netrc.Anonymous HTTPS (permitted in
communityandnonemodes for public reads; rejected ingooglermode with exit code4).
LUCI Buildbucket & LogDog#
LUCI Buildbucket pRPC requests (pr checks, pr view, pr status,
run view, run list, run rerun) and LogDog log requests look up
OAuth2 tokens in the following order:
GHISH_LUCI_TOKENorLUCI_TOKENenvironment variable.luci-auth token(located onPATHor in the repository’s bootstrapped CIPD environment).gcloud auth application-default print-access-tokenorgcloud auth print-access-token.
In googler mode, an active LUCI OAuth2 token is required so that
buildbucket.v2.Builds/SearchBuilds returns both public and internal CQ
builders. To log in or refresh your LUCI session:
$ luci-auth login
Google Issue Tracker (Buganizer)#
./gh issue looks up credentials in the following order:
GHISH_ISSUE_TOKENorBUGANIZER_TOKENenvironment variable.luci-auth token -scopes "https://www.googleapis.com/auth/buganizer https://www.googleapis.com/auth/cloud-platform"gcloud auth application-default print-access-tokenorgcloud auth print-access-token.
When sso_client is on PATH, requests use
https://issuetracker.corp.googleapis.com/v1 to access both public and
internal Buganizer components.