Blixt Documentation v2.9

Create a bucket

  1. Open the GCS Console.
  2. Click Create bucket.
  3. Choose a location and pick a storage class (Standard is fine for most use cases).
  4. Click Create.

Credentials and permissions

Running inside GCE or GKE? BlixtFS supports Application Default Credentials (ADC) out of the box. GCE instances and GKE pods automatically authenticate to GCS via the metadata server, using the service account attached to the VM or workload. There are no credential files to manage — just make sure the service account has the Storage Object Admin role on your bucket.

Using gcloud on your machine? If you have run gcloud auth application-default login, BlixtFS picks up your default credentials automatically. This is convenient for development and testing.

Other environments? You will need to create and manage a service account key:

  1. On the Service Accounts page, create a new service account.
  2. Grant it the Storage Object Admin role on your bucket.
  3. Click Keys → Add Key → JSON to download a key file.
  4. Point BlixtFS at this JSON key file during setup.

Pub/Sub permissions

GCS requires Pub/Sub permissions to be configured for the project. BlixtFS creates a Pub/Sub channel to receive updates from GCS, but by default GCS does not have permission to publish to Pub/Sub. The following commands authorise GCS to send Pub/Sub messages to BlixtFS. See the GCS documentation for background.

  1. Find the GCS service account for your project. Replace PROJECT with your GCP project name. Use the output as SERVICE-ACCOUNT in the next command.
gcloud storage service-agent --project=PROJECT
  1. Grant the roles/pubsub.publisher role to the GCS service account:
gcloud pubsub topics add-iam-policy-binding projects/PROJECT/topics/blixtfs \
  --member="serviceAccount:SERVICE-ACCOUNT" \
  --role="roles/pubsub.publisher"

Project

The Google Cloud project the buckets belong to, and the project the blixtfs Pub/Sub topic is created in. Set it with GCP_PROJECT, --gcp_project or cloud.gcp.project.