Skip to content

fix: keep google-auth transport imports out of Agent import - #7359

Closed
harshal-96 wants to merge 1 commit into
google:mainfrom
harshal-96:fix/lazy-gcp-metadata-requests
Closed

harshal-96 wants to merge 1 commit into
google:mainfrom
harshal-96:fix/lazy-gcp-metadata-requests

Conversation

@harshal-96

Copy link
Copy Markdown

Please ensure you have read the contribution guide before creating a pull request.

Link to Issue or Description of Change

2. Or, if no issue exists, describe the change:

Problem:

test_import_loading.py::test_entry_point_loads_only_allowlisted_packages[agent] has failed on main since 8d8bbd2 (feat: default Vertex project from GCP metadata). No completed Continuous Integration run on main has passed since that commit: 11 failed and the others were cancelled. For example, https://github.com/google/adk-python/actions/runs/36484921667 fails this test on all five Python versions.

The cause: src/google/adk/utils/_gcp_metadata.py imports google.auth.compute_engine._metadata and google.auth.transport.requests at module level. from google.adk.agents import Agent reaches that module through models/google_llm.py, so every ADK process now loads requests, urllib3, charset_normalizer and cryptography at startup.

This is not in any release yet (2.10.0 has no _gcp_metadata.py), so fixing it now keeps it out of the next one.

Solution:

Both imports move into get_project_id_from_metadata, the only function that uses them, inside its existing try. If an import fails, the lookup returns None like any other lookup failure.

Each of the two imports on its own loads all four packages, so both have to move. The tests patch ping and get on the google-auth _metadata module itself, so they are unaffected.

Testing Plan

Unit Tests:

  • I have added or updated unit tests for my change.
  • All unit tests pass locally.

No new test: the existing test_import_loading.py covers this, and it fails on main and passes with this change.

All results below are from environments built like CI (uv sync --extra test --no-install-package lancedb):

  • tests/unittests/test_import_loading.py, tests/unittests/utils, tests/unittests/models/test_google_llm.py and tests/unittests/cli/utils/test_envs.py: 645 passed on Python 3.10, 3.11, 3.12, 3.13 and 3.14. On main the same run gives 1 failed, 644 passed on each version.
  • Full tests/unittests on Python 3.12: 16387 passed, 2 failed. The two failures are the LiveKit run_live tests that also time out on main on my machine, a separate bug in _merge_live_event_streams (Closing a live event stream early can hang forever in _merge_live_event_streams #7357). main itself gives 16386 passed, 3 failed: those two plus the test fixed here.
  • mypy, compared the way CI does it: no new errors.

Manual End-to-End (E2E) Tests:

python -c "import sys; from google.adk.agents import Agent; print(sorted(m for m in ('requests', 'urllib3', 'cryptography', 'charset_normalizer') if m in sys.modules))"
  • On main: ['charset_normalizer', 'cryptography', 'requests', 'urllib3']
  • With this change: []

I have not run it on a Compute Engine VM against a real metadata server. The lookup code itself is unchanged; only where the two modules are imported moves.

Checklist

  • I have read the CONTRIBUTING.md document.
  • I have performed a self-review of my own code.
  • I have commented my code, particularly in hard-to-understand areas.
  • I have added tests that prove my fix is effective or that my feature works.
  • New and existing unit tests pass locally with my changes.
  • I have manually tested my changes end-to-end.
  • Any dependent changes have been merged and published in downstream modules.

_gcp_metadata imported google.auth.compute_engine._metadata and
google.auth.transport.requests at module level. Both load requests,
urllib3 and cryptography, so `from google.adk.agents import Agent`
started paying for them and test_import_loading failed on main.

Import them inside get_project_id_from_metadata, the only user.
@GWeale

GWeale commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

thanks @harshal-96 for catching this and for sending the fix first. the same change landed in 41bebdc, which moves both google-auth imports into get_project_id_from_metadata, and it shipped in v2.11.0. please open a new issue if this is still happening.

@GWeale GWeale closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants