Shared Google Workspace plumbing for Isaac โ OAuth for the Google user, the Pub/Sub push door and durable inbox, registrations and renewal, health. Knows nothing of Chat or Gmail.
Depends on isaac-foundation and
isaac-agent. Contributes :isaac.google.
Part of the Google Workspace comms epic (isaac-bv1l).
- Module (
isaac.google.module/create-module), manifest id:isaac.google. - OAuth scopes berth, Pub/Sub handler berth, Workspace Events registration/renewal.
- Isaac publishes nothing to Pub/Sub. A Cloud Scheduler job publishes the
heartbeat to the organization's topic as a Google APIs service account inside
GCP โ no exported key, so nothing for
constraints/iam.disableServiceAccountKeyCreationto refuse โ and Isaac watches for its arrival againstgoogle.<org>.health.heartbeat.expected-interval-ms(isaac-clly; the Cloud Scheduler runbook is indoc/rollout.md). - No Cloud Platform scope rides on the human's login: one there drags the whole Google grant under the Workspace's Cloud reauthentication clock (isaac-ey6q, isaac-286x).
- Further work is planned in the beans under isaac-bv1l.
Sibling checkouts expected:
plan/
isaac-foundation/
isaac-agent/
isaac-http/
isaac-google/ # this repo
bb hooks:install # once, on a fresh checkout
bb spec
bb features
bb ciFrom the JVM:
clj -M:spec
clj -M:featuresio.github.slagyr/isaac-google {:local/root "../isaac-google"}
;; or {:git/url "https://github.com/slagyr/isaac-google.git" :git/sha "..."}