google: add --google-no-service-account

What

--google-no-service-account: the instance request has no serviceAccounts field, on both the Instances.Insert and RegionInstances.BulkInsert paths. GCE attaches no service account and the metadata server has no access token. If --google-service-account or --google-scopes is also set to a non-default value, the driver warns that it ignores them.

Why

The runner fleet's ephemeral VMs get a service account with logging.write and monitoring.write scopes. It has no IAM bindings and nothing on the VM uses it, but a job container can fetch its token from the metadata server, and VPC firewall rules cannot block that. With no service account there is no token.

gitlab-com/gl-infra/production-engineering#29891

Testing

Runner sandbox, stock cos-125-lts on t2d-standard-2, docker-machine from this branch with the flag in MachineOptions: VMs show no service account in gcloud compute instances list, the boot canary passed, and from inside a job instance/service-accounts/ is an empty list and instance/service-accounts/default/token returns 404. Other metadata (instance/machine-type) still answers.

Edited by Igor

Merge request reports

Loading
Loading