Skip to content

Router authn/z part 2.5: podcertcontroller: Don't load pod in podidentity signer - #2389

Open
Taahir Ahmed (ahmedtd) wants to merge 3 commits into
agent-substrate:mainfrom
ahmedtd:router-authnz-2.5
Open

Taahir Ahmed (ahmedtd) wants to merge 3 commits into
agent-substrate:mainfrom
ahmedtd:router-authnz-2.5

Conversation

@ahmedtd

Copy link
Copy Markdown
Collaborator

We should rely on the checks enforced by kube-apiserver. We don't need to double-check whether the pod exists.

Upcoming e2e test changes will rely on the fact that non-Kubelet clients are allowed to create arbitary PodCertificateRequests, even if the pod or service account they reference does not exist. This will allow the test code running in Github Actions (or on the developer's machine) to authenticate to the router running within the cluster.

…router

Add --ingress-auth-mode=:{static-mtls|insecure}.

In static-mtls all clients must present a SPIFFE certificate (validated
with --ingress-client-ca-file).  The SPIFFE ID is checked against an
allowlist (in --ingress-allowed-spiffe-ids).

In static-mtls mode, the router will refuse to start with a plaintext
listener.
Add --ingress-auth-mode to ate-setup, to pick between static-mtls and
insecure modes for the ingress router.

By default, static-mtls mode is set up to trust certificates issued by
podidentity.podcert.ate.dev/identity, which is the most convenient
option for setups running within the scope of a single cluster.
We should rely on the checks enforced by kube-apiserver.  We don't need
to double-check whether the pod exists.

Upcoming e2e test changes will rely on the fact that non-Kubelet
clients are allowed to create arbitary PodCertificateRequests, even if
the pod or service account they reference does not exist.
@ahmedtd Taahir Ahmed (ahmedtd) changed the title Router authn/z 2.5: podcertcontroller: Don't load pod in podidentity signer Router authn/z part 2.5: podcertcontroller: Don't load pod in podidentity signer Oct 9, 2026
@EItanya

Eitan Yarmush (EItanya) commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Taahir Ahmed (@ahmedtd), is seems like the core function of this PR is actually the downstream mTLS changes to ingress. Can we update the description/purpose accordingly?

Edit: I see this is stacked?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants