Storage
Google Cloud Storage
Store watermarked files in your own Google Cloud Storage bucket. Grant Etchv access without a private key (recommended) or with a service account key.
Connect with keyless Workload Identity Federation or a service account JSON key. Federation lets Etchv sign in to Google Cloud with its AWS identity, so no private key is shared. Keyless access uses short-lived tokens. It works even when your organization blocks service account keys.
Grant access to your bucket
Create a service account used only for Etchv. On the bucket, grant it a custom role with storage.objects.create and storage.objects.get. Limit the role to your prefix and the small test file (probe) Etchv uses to check the connection. See Google’s permission reference.
Connect without a private key (recommended)
- Enable the IAM, IAM Service Account Credentials and Security Token Service APIs.
- Create a dedicated workload identity pool with an AWS provider.
- In Dashboard storage, choose Google Cloud Storage → Keyless, or send this to
POSTwith a/storage /destinations storage:writeowner/admin key:
{
"name": "Production GCS",
"provider": "gcs",
"bucket": "YOUR_BUCKET",
"prefix": "etchv",
"visibility": "private",
"gcs_auth": "workload_identity",
"gcs_workload_identity_provider": "projects/123456789/locations/global/workloadIdentityPools/etchv-pool/providers/aws-etchv",
"gcs_service_account": "etchv-storage@your-project.iam.gserviceaccount.com"
}Use the project number in the provider resource. Save the returned aws_principal_arn and gcs_subject. The subject is unique to your Etchv organization and is the same for all its destinations.
Trust the exact Etchv identity
For returned role arn:aws:iam::AWS_ACCOUNT_ID:role, configure:
| Setting | Value |
|---|---|
| AWS account | AWS_ACCOUNT_ID |
| Attribute mapping | google. |
| Attribute condition | assertion. |
- AWS account
- Value
AWS_ACCOUNT_ID
- Attribute mapping
- Value
google.subject = assertion. arn. extract( 'assumed-role /ROLE_NAME /{session}')
- Attribute condition
- Value
assertion.arn. startsWith( 'arn:aws:sts:: AWS_ACCOUNT_ID:assumed-role /ROLE_NAME /etchv-')
Grant Workload Identity User (roles) on the service account to this exact principal, using the returned subject:
principal://iam.googleapis.com/projects/PROJECT_NUMBER/locations/global/workloadIdentityPools/POOL_ID/subject/GCS_SUBJECT
Click Test connection or call POST . The probe checks write and read access. IAM changes can take a few minutes to apply, so wait and try again if needed. A destination that is not verified cannot receive new requests. See Google’s AWS federation guide.
Store outputs
Pass the destination ID in your embedding request. SDK storage options work unchanged.
| Visibility | Returned location |
|---|---|
| Private | gs: |
| Already public | URI plus https: |
- Private
- Returned location
gs:/ /bucket /key
- Already public
- Returned location
- URI plus
https:/ /storage. googleapis. com /bucket /key
Etchv does not change IAM or ACLs. Generation preconditions prevent overwrites: Etchv writes only when no object with that name exists yet. Your bucket controls how long files are kept. Deleting an Etchv record does not delete its file in your bucket.
Optional: service account JSON keys
Choose Service account JSON key, or use these request fields instead of the federation fields:
| Field | Value |
|---|---|
gcs_auth | "service_account_key" |
credentials | Full service account JSON encoded as a string |
gcs_auth- Value
"service_account_key"
credentials- Value
- Full service account JSON encoded as a string
The key must use https:. Etchv encrypts credentials and never returns them. A general Google API key will not work.
Rotate credentials or change authentication mode
Replace credentials with PATCH , then verify before revoking the old key. Keyless destinations do not accept credential uploads. You can't change the authentication mode or provider details later. To change them, create a new destination.