Created June 30, 2023 00:55
ALTS modified GRPC helloworld example (grpc-go/examples/helloworld from
// Package main implements a client for Greeter service.
package main
import (
pb ""
const (
defaultName = "world"
hardCodedCredential = "myHardCodedCredential"
var (
addr = flag.String("addr", "localhost:50051", "the address to connect to")
name = flag.String("name", defaultName, "Name to greet")
func main() {
// Set up a connection to the server.
altsTC := alts.NewClientCreds(alts.DefaultClientOptions())
conn, err := grpc.Dial(*addr, grpc.WithTransportCredentials(altsTC))
if err != nil {
log.Fatalf("did not connect: %v", err)
defer conn.Close()
c := pb.NewGreeterClient(conn)
// Add metadata with the credential to the context
ctx := metadata.AppendToOutgoingContext(context.Background(), "credential", hardCodedCredential)
// Contact the server and print out its response.
ctx, cancel := context.WithTimeout(context.Background(), time.Second)
defer cancel()
r, err := c.SayHello(ctx, &pb.HelloRequest{Name: *name})
if err != nil {
log.Fatalf("could not greet: %v", err)
log.Printf("Greeting: %s", r.GetMessage())
// Package main implements a server for Greeter service.
package main
import (
pb ""
var (
port = flag.Int("port", 50051, "The server port")
const (
// Replace with your hardcoded credential string
hardCodedCredential = "myHardCodedCredential"
// server is used to implement helloworld.GreeterServer.
type server struct {
// SayHello implements helloworld.GreeterServer
func (s *server) SayHello(ctx context.Context, in *pb.HelloRequest) (*pb.HelloReply, error) {
md, _ := metadata.FromIncomingContext(ctx)
if !checkCredential(md) {
return nil, fmt.Errorf("unauthorized")
log.Printf("Received: %v", in.GetName())
return &pb.HelloReply{Message: "Hello " + in.GetName()}, nil
// checkCredential checks if the incoming request has the correct credential.
func checkCredential(md metadata.MD) bool {
values := md.Get("credential")
for _, v := range values {
if strings.EqualFold(v, hardCodedCredential) {
return true
return false
func main() {
lis, err := net.Listen("tcp", fmt.Sprintf(":%d", *port))
if err != nil {
log.Fatalf("failed to listen: %v", err)
// Set up the server with ALTS credentials
altsTC := alts.NewServerCreds(alts.DefaultServerOptions())
s := grpc.NewServer(grpc.Creds(altsTC))
pb.RegisterGreeterServer(s, &server{})
log.Printf("server listening at %v", lis.Addr())
if err := s.Serve(lis); err != nil {
log.Fatalf("failed to serve: %v", err)
I was curious about how the lib determines that it's in GCP. As it turns out, it uses manufacturer info to do it without any network calls needed:

