568c04f7c1
* docs: reorganize sidebar navigation and clean up install pages` * feat: enhance index hero styling and update features documentation * docs: update installation guides and enhance table styling * docs: enhance investigation documentation and improve interactive shell descriptions * Update documentation for API, community giveaway, CloudOpsBench, deployment, FAQ, PR review flow, and Python API * Update documentation for background investigations, closed-loop learning, cron scheduling, and integrations overview * Introducing structured flow for the documentation * docs: update integration documentation for various services --------- Co-authored-by: Vaibhav Upreti <vaibhav.upreti16@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
122 lines
3.6 KiB
Plaintext
122 lines
3.6 KiB
Plaintext
---
|
|
title: "Google Docs"
|
|
description: "Connect Google Docs so OpenSRE can write investigation reports to your Google Drive"
|
|
---
|
|
|
|
## Overview
|
|
|
|
OpenSRE can write investigation findings directly to Google Drive as formatted Google Docs — creating a persistent, shareable record of each incident investigation linked to your team's existing Drive folder.
|
|
|
|
## Prerequisites
|
|
|
|
- Google Cloud project with the Google Drive API enabled
|
|
- Service account with access to a shared Drive folder
|
|
|
|
## Setup
|
|
|
|
There is no dedicated `opensre integrations setup google_docs` command today. Configure Google Docs through the onboarding wizard, environment variables, or the persistent store.
|
|
|
|
### Option 1: Onboarding wizard
|
|
|
|
```bash
|
|
opensre onboard
|
|
```
|
|
|
|
Select **Google Docs** when prompted and provide your credentials file path and folder ID.
|
|
|
|
### Option 2: Environment variables
|
|
|
|
Add to your `.env`:
|
|
|
|
```bash
|
|
GOOGLE_CREDENTIALS_FILE=/path/to/service-account.json
|
|
GOOGLE_DRIVE_FOLDER_ID=your-google-drive-folder-id
|
|
```
|
|
|
|
| Variable | Default | Description |
|
|
| --- | --- | --- |
|
|
| `GOOGLE_CREDENTIALS_FILE` | — | **Required.** Path to the service account JSON file |
|
|
| `GOOGLE_DRIVE_FOLDER_ID` | — | **Required.** Google Drive folder ID for investigation reports |
|
|
|
|
### Option 3: Persistent store
|
|
|
|
```json
|
|
{
|
|
"version": 1,
|
|
"integrations": [
|
|
{
|
|
"id": "google-docs-prod",
|
|
"service": "google_docs",
|
|
"status": "active",
|
|
"credentials": {
|
|
"credentials_file": "/path/to/service-account.json",
|
|
"folder_id": "1BxiMVs0XRA5nFMdKvBdBZjgmUUqptlbs74OgVE2upms"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
```
|
|
|
|
## Credentials
|
|
|
|
### Creating a service account
|
|
|
|
1. In Google Cloud Console, go to **IAM & Admin** → **Service Accounts**
|
|
2. Click **Create Service Account**
|
|
3. Give it a name (for example `opensre-docs`) and click **Create**
|
|
4. Skip role assignment and click **Done**
|
|
5. Click on the service account → **Keys** → **Add Key** → **Create new key** (JSON)
|
|
6. Download the JSON file
|
|
|
|
Auth uses a **service account** only (Google Docs + Drive API scopes) — not end-user OAuth.
|
|
|
|
### Granting Drive folder access
|
|
|
|
1. In Google Drive, open the folder where reports should be saved
|
|
2. Click **Share**
|
|
3. Add the service account email (for example `opensre-docs@your-project.iam.gserviceaccount.com`)
|
|
4. Set the permission to **Editor**
|
|
|
|
### Finding the folder ID
|
|
|
|
The folder ID appears in the Drive URL:
|
|
|
|
`https://drive.google.com/drive/folders/<folder-id>`
|
|
|
|
## Investigation tools
|
|
|
|
| Tool | What it does |
|
|
| --- | --- |
|
|
| `create_google_docs_incident_report` | Creates a Google Doc in the configured Drive folder and inserts the investigation / postmortem content. Can optionally share the doc (`reader` / `writer` / `owner`). |
|
|
|
|
## Verify
|
|
|
|
```bash
|
|
opensre integrations verify google_docs
|
|
```
|
|
|
|
Expected output:
|
|
|
|
```
|
|
Service: google_docs
|
|
Status: passed
|
|
Detail: Connected to Drive folder 1BxiMVs0XRA5nFMdKvBdBZjgmUUqptlbs74OgVE2upms (3 items in folder)
|
|
```
|
|
|
|
Verification probes Drive access to the configured folder.
|
|
|
|
## Troubleshooting
|
|
|
|
| Symptom | Fix |
|
|
| --- | --- |
|
|
| **Credentials file not found** | Check the path in `GOOGLE_CREDENTIALS_FILE` — use an absolute path |
|
|
| **403 Forbidden** | The service account hasn't been added to the Drive folder with Editor access |
|
|
| **Drive API not enabled** | Enable the **Google Drive API** in your Google Cloud project |
|
|
| **Folder not found** | Confirm the folder ID and that the service account has access |
|
|
|
|
## Security
|
|
|
|
- Keep the service account JSON file outside of your repository — add it to `.gitignore`.
|
|
- Grant the service account access **only** to the specific Drive folder it needs.
|
|
- Rotate the service account key periodically via Google Cloud Console.
|