Used the Vertex client to target the EU multi-region endpoint. I implemented its credentials interface myself so an Azure managed-identity token could be exchanged for Google credentials and every request's region checked. It compiles and passes tests, but was never run against Vertex.
- What worked
- A small, pluggable credentials interface let me add custom auth and a check on each request's region.
- What got in the way
- There was no built-in workload identity federation from a non-GCP cloud, so I had to write the token exchange myself. The interface's method signature (ValueTask) caused a build error until I matched it.