google-cloud-storage-connector
Service icon

Google Cloud Storage Connector

Stable version 1.6.1 (Compatible with OutSystems 11)
Uploaded
 on 9 Oct (16 hours ago)
 by 
5.0
 (3 ratings)
google-cloud-storage-connector

Google Cloud Storage Connector

Details
Integrate Google Cloud Storage to easily store and retrieve objects.
Read more

Google Cloud Storage for OutSystems 11, with keyless authentication.

Manage buckets and objects in Google Cloud Storage directly from your OutSystems applications. Built on the official Google Cloud .NET SDK, the connector authenticates with Workload Identity Federation, so no Google key exists anywhere, or with a service account key. It covers the full object and bucket lifecycle, including folders, custom metadata and signed URLs.


Features

  • Keyless authentication: Workload Identity Federation with any OIDC identity provider (Entra ID, Okta, Auth0, Keycloak and others), server to server. Service account keys are still supported.

  • Full object lifecycle: upload, download, list, copy, move and delete objects, and delete a whole folder by prefix.

  • Large buckets: page through results, or browse folder by folder with a delimiter.

  • Metadata: read a file's size, hashes, versioning and timestamps without downloading it, and store, read and update your own key-value metadata.

  • Bucket management: create, list, check and delete buckets.

  • Signed URLs: temporary V4 links for download, upload or delete, optionally locked to one content type.

  • Clear errors: messages say what to fix, such as a missing bucket, a missing IAM role or a rejected credential.


Object Actions

  • Object_Upload: uploads binary data with its content type and optional custom metadata. Overwrites an existing object.

  • Object_Download: returns an object's content and content type.

  • Object_List: lists objects, with an optional prefix. Set MaxResults and pass NextPageToken back as PageToken to page through large buckets; set Delimiter to / to get the folders in PrefixList.

  • Object_Exists: checks whether an object exists, without downloading it.

  • Object_GetMetadata: returns size, content type, hashes, generation, storage class, timestamps and custom metadata, without downloading the content.

  • Object_UpdateMetadata: changes content type, encoding, disposition, cache control and custom metadata without re-uploading. Empty inputs leave a field unchanged; a metadata entry with an empty Value removes that key.

  • Object_Delete: permanently deletes an object.

  • Object_DeleteByPrefix: deletes every object under a prefix (a folder and its subfolders) and returns the count. The prefix can't be empty.

  • Object_Copy: copies an object within or between buckets without downloading it.

  • Object_Move: copies an object, then deletes the source. Use the same bucket to rename.

  • Object_GetSignedUrl: creates a signed URL for Download, Upload or Delete, valid from 1 minute to 7 days. For uploads, ContentType makes the URL accept only that content type.

Bucket Actions

  • Bucket_List: lists the buckets in the project.

  • Bucket_Create: creates a bucket in a location such as US, EU or asia-east1.

  • Bucket_Exists: checks whether a bucket exists and is accessible.

  • Bucket_Delete: deletes an empty bucket.


Prerequisites

  1. A Google Cloud project with billing enabled.

  2. A service account with the roles your operations need: Storage Object Admin (objects) and Storage Admin (buckets).

  3. For Workload Identity Federation: an OIDC identity provider that issues signed JWTs, and, for the federated identity, Workload Identity User on the service account plus Service Account Token Creator if you generate signed URLs.

  4. For a service account key: a downloaded JSON key for the service account. Signed URLs are signed locally and need no extra role.

Authentication Setup

Create one server action or function that builds a GCS_Authentication record from your Site Properties, and pass it to every call. To change method later, you only change that record. AuthenticationMethod selects the method; leave it empty for a service account key.

Workload Identity Federation (recommended)

The connector gets a JWT from your identity provider with the OAuth 2.0 client-credentials grant, exchanges it with Google's Security Token Service, and acts as your service account with short-lived tokens. Set:

  • AuthenticationMethod: WorkloadIdentityFederation

  • ProjectId: your Google Cloud project ID

  • WorkloadIdentityProvider: //iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL/providers/PROVIDER

  • ServiceAccountEmail: the service account the connector acts as

  • TokenEndpoint, ClientId, ClientSecret: your identity provider's token endpoint (https) and app registration

  • Scope, Audience: optional values for the token request, if your provider needs them

  • SubjectToken: optional JWT you already have; when set, TokenEndpoint, ClientId and ClientSecret aren't needed

The OutSystems server must reach your provider's token endpoint, sts.googleapis.com and iamcredentials.googleapis.com. The full Google Cloud setup, with gcloud commands, is in the README on GitHub.

Service account key

Leave AuthenticationMethod empty and map these values from the service account JSON key:

  • project_id -> ProjectId

  • client_email -> ClientEmail

  • private_key -> PrivateKey (the full string, including the -----BEGIN PRIVATE KEY----- header)

Security tip: keep PrivateKey and ClientSecret in encrypted Site Properties or an encrypted database table, and never hard-code them.


Best Practices

  • Prefer keyless: with Workload Identity Federation there is no long-lived Google key to leak or rotate.

  • Large files: use Object_GetSignedUrl so users transfer directly to and from Google, sparing server memory and bandwidth.

  • Pre-flight checks: call Object_GetMetadata before a download to read size and content type without transferring the file.

  • Per-environment config: fill the Authentication record from Site Properties so Dev, QA and Prod each target their own project and bucket.


Source Code

This connector is open source under the MIT license. Browse the code, report issues, or contribute on GitHub:

github.com/promonteiro89/google-cloud-storage-connector-o11

Release notes (1.6.1)

Google now recommends its latest Cloud Storage client libraries, which validate upload checksums end to end by default. This release adopts them. It’s a drop-in replacement for 1.6.0.

Improved

  • Corrupted uploads are rejected before they’re stored. Object_Upload sends a CRC32C checksum of the exact file bytes, and Google rejects the upload if the data changed in transit.
    • Nothing is stored, and an existing file with the same name is never overwritten with bad data.
    • Before, the check ran after the file was stored, and an overwritten file could be lost.
  • Clear error message. A rejected upload now explains that nothing was stored and that the upload can be retried.


Updated

  • Google Cloud Storage client 5.0.0 (Google’s recommended minimum for .NET).
  • The other Google client libraries, refreshed to their latest releases.


Good to know

  • Uploads through signed URLs go directly from the browser to Google, so they aren’t covered by this automatic check.
License (1.6.1)
Reviews (0)
Team
Other assets in this category