Files
Devesh 568c04f7c1 refresh docs — shared integration flow, clearer guides, and accuracy fixes (#4697)
* docs: reorganize sidebar navigation and clean up install pages`

* feat: enhance index hero styling and update features documentation

* docs: update installation guides and enhance table styling

* docs: enhance investigation documentation and improve interactive shell descriptions

* Update documentation for API, community giveaway, CloudOpsBench, deployment, FAQ, PR review flow, and Python API

* Update documentation for background investigations, closed-loop learning, cron scheduling, and integrations overview

* Introducing structured flow for the documentation

* docs: update integration documentation for various services

---------

Co-authored-by: Vaibhav Upreti <vaibhav.upreti16@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-17 13:50:26 +01:00

122 lines
3.6 KiB
Plaintext

---
title: "Google Docs"
description: "Connect Google Docs so OpenSRE can write investigation reports to your Google Drive"
---
## Overview
OpenSRE can write investigation findings directly to Google Drive as formatted Google Docs — creating a persistent, shareable record of each incident investigation linked to your team's existing Drive folder.
## Prerequisites
- Google Cloud project with the Google Drive API enabled
- Service account with access to a shared Drive folder
## Setup
There is no dedicated `opensre integrations setup google_docs` command today. Configure Google Docs through the onboarding wizard, environment variables, or the persistent store.
### Option 1: Onboarding wizard
```bash
opensre onboard
```
Select **Google Docs** when prompted and provide your credentials file path and folder ID.
### Option 2: Environment variables
Add to your `.env`:
```bash
GOOGLE_CREDENTIALS_FILE=/path/to/service-account.json
GOOGLE_DRIVE_FOLDER_ID=your-google-drive-folder-id
```
| Variable | Default | Description |
| --- | --- | --- |
| `GOOGLE_CREDENTIALS_FILE` | — | **Required.** Path to the service account JSON file |
| `GOOGLE_DRIVE_FOLDER_ID` | — | **Required.** Google Drive folder ID for investigation reports |
### Option 3: Persistent store
```json
{
"version": 1,
"integrations": [
{
"id": "google-docs-prod",
"service": "google_docs",
"status": "active",
"credentials": {
"credentials_file": "/path/to/service-account.json",
"folder_id": "1BxiMVs0XRA5nFMdKvBdBZjgmUUqptlbs74OgVE2upms"
}
}
]
}
```
## Credentials
### Creating a service account
1. In Google Cloud Console, go to **IAM & Admin** → **Service Accounts**
2. Click **Create Service Account**
3. Give it a name (for example `opensre-docs`) and click **Create**
4. Skip role assignment and click **Done**
5. Click on the service account → **Keys** → **Add Key** → **Create new key** (JSON)
6. Download the JSON file
Auth uses a **service account** only (Google Docs + Drive API scopes) — not end-user OAuth.
### Granting Drive folder access
1. In Google Drive, open the folder where reports should be saved
2. Click **Share**
3. Add the service account email (for example `opensre-docs@your-project.iam.gserviceaccount.com`)
4. Set the permission to **Editor**
### Finding the folder ID
The folder ID appears in the Drive URL:
`https://drive.google.com/drive/folders/<folder-id>`
## Investigation tools
| Tool | What it does |
| --- | --- |
| `create_google_docs_incident_report` | Creates a Google Doc in the configured Drive folder and inserts the investigation / postmortem content. Can optionally share the doc (`reader` / `writer` / `owner`). |
## Verify
```bash
opensre integrations verify google_docs
```
Expected output:
```
Service: google_docs
Status: passed
Detail: Connected to Drive folder 1BxiMVs0XRA5nFMdKvBdBZjgmUUqptlbs74OgVE2upms (3 items in folder)
```
Verification probes Drive access to the configured folder.
## Troubleshooting
| Symptom | Fix |
| --- | --- |
| **Credentials file not found** | Check the path in `GOOGLE_CREDENTIALS_FILE` — use an absolute path |
| **403 Forbidden** | The service account hasn't been added to the Drive folder with Editor access |
| **Drive API not enabled** | Enable the **Google Drive API** in your Google Cloud project |
| **Folder not found** | Confirm the folder ID and that the service account has access |
## Security
- Keep the service account JSON file outside of your repository — add it to `.gitignore`.
- Grant the service account access **only** to the specific Drive folder it needs.
- Rotate the service account key periodically via Google Cloud Console.