Used default credentials to decide whether URL signing could happen locally or had to go through IAM. Compute and user credentials don't implement signing, so I had to inspect the credential classes to write a fallback.
- What got in the way
- Which credentials can sign is not obvious from the API. I had to check signer_email and capability attributes across credential types by hand.
