Skip to content

feat(chart): further credential providers for the egress gateway - #104

Closed
QuentinBisson wants to merge 3 commits into
giantswarmfrom
feat/egress-credential-providers
Closed

QuentinBisson wants to merge 3 commits into
giantswarmfrom
feat/egress-credential-providers

Conversation

@QuentinBisson

@QuentinBisson QuentinBisson commented Oct 1, 2026 •

Copy link
Copy Markdown

Problem

The egress gateway resolves ate-secret:// URIs through a list of credential providers keyed by URI authority, but the chart renders only the bundled k8s.io one. kagent needs a second provider that answers for the caller of the current turn, so the caller's bearer is injected at egress and never enters the actor (giantswarm/giantswarm#38054).

Change

credentialProvider.additionalProviders adds providers on both egress listeners. uriAuthority must be a lowercase DNS name and host must be <service>.<namespace>.svc:<port>, the name the provider's servicedns.podcert.ate.dev serving certificate carries; the gateway presents its pod identity, which the provider must require. The bundled provider cannot be replaced and an authority cannot appear twice. The default render is unchanged.

@teemow

teemow commented Oct 1, 2026

Copy link
Copy Markdown
Member

From Timo's agent: #106 adds the chart's otel env to the egress ext-proc container in atenet-egress.yaml (the container's env, not your ConfigMap hunks) and one FORK.md carried-patch row. Is it OK to merge ahead of this PR?

@teemow

teemow commented Oct 1, 2026

Copy link
Copy Markdown
Member

From Timo's agent: two more for the same issue, #107 (serverboot honors OTEL_TRACES_EXPORTER=none) and #108 (ate-controller turns ateom's exporters off without an endpoint). Each adds one FORK.md carried-patch row at the end of the table and leaves your files otherwise alone. OK to merge them ahead of this PR as well?

@teemow

teemow commented Oct 2, 2026

Copy link
Copy Markdown
Member

Question from Team Bumblebee's agents (written by an agent on Timo's behalf): may the agent merge #106, #107 and #108 (the lab OTLP endpoint for agent-platform#463; green, they touch FORK.md and #106 touches atenet-egress.yaml, files of this draft), or do you want them rebased after this PR lands?

@QuentinBisson

Copy link
Copy Markdown
Author

Parked: git as the person is postponed. Upstream Substrate is redesigning this area (actor JWT injection merged in agent-substrate#1960, token exchange of the actor JWT in agent-substrate#1661, the actor JWT contract in agent-substrate#1756), which likely supersedes this provider design, and this fork line has to re-pin past agent-substrate#1809 before it can follow. Kept as a draft so it can resume in place; tracking in giantswarm/giantswarm#38064.

@teemow

teemow commented Oct 2, 2026

Copy link
Copy Markdown
Member

From Timo's agent: while this draft is parked, is it OK for you if #106, #107 and #108 land first on the same files (FORK.md rows, the egress ext-proc env, the otel comment in values.yaml and the README row), and you rebase when you resume?

@QuentinBisson

Copy link
Copy Markdown
Author

sure

@teemow

teemow commented Oct 6, 2026

Copy link
Copy Markdown
Member

Written by an agent: #145 (a carry of kagent-dev#47) also edits the credentialProviders block in atenet-egress.yaml. It turns the bundled k8s.io entry into a range over k8s.io and google-access-token.k8s.io and touches nothing of this PR. May #145 land first, with whichever lands second taking the small rebase, or would you rather fold it into this PR?

credentialProvider.additionalProviders adds providers to the egress
gateway's credentialProviders list beside the bundled kubernetes.io one,
on both the HTTPS and the HTTP listener. The gateway dials each with its
pod identity and verifies a servicedns.podcert.ate.dev serving
certificate. An entry needs uriAuthority and host, cannot replace
kubernetes.io and cannot name an authority twice. The default render is
unchanged.
uriAuthority must be a lowercase DNS name and host must be
<service>.<namespace>.svc:<port>, the name a servicedns serving
certificate carries, so a value can neither inject YAML into the gateway
config nor name a provider the gateway can never match or verify. The
values and README say which client identity the provider must require.
@teemow

teemow commented Oct 10, 2026

Copy link
Copy Markdown
Member

Written by an agent: merged as #248, which carries these three commits with your authorship onto the line after its re-pin (this branch conflicted with its base).

@teemow teemow closed this Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants