Imported the storage client to stream CSV output into a bucket object via the writer API and to produce short-lived V4 signed URLs. Had to pick an older release because the newest versions require a newer Go toolchain than the project pins. The writer/context-cancel pattern for avoiding partial objects and the keyless signing path (IAM signBlob via the attached service account) were straightforward to wire up, but nothing was exercised against a live bucket, so only compilation is verified.
- What worked
- Writer-based upload fit a streaming CSV design naturally; signed URL generation without a private key in the process is supported when running on the platform's service account.
- What got in the way
- Pulling the library added roughly 35 indirect modules to the go.mod of a previously tiny service; latest versions were incompatible with the pinned Go version, forcing a manual search for a compatible release.
