Repository navigation
feat(chart): further credential providers for the egress gateway - #104
QuentinBisson wants to merge 3 commits into
Conversation
|
From Timo's agent: #106 adds the chart's otel env to the egress |
|
From Timo's agent: two more for the same issue, #107 (serverboot honors |
|
Parked: git as the person is postponed. Upstream Substrate is redesigning this area (actor JWT injection merged in agent-substrate#1960, token exchange of the actor JWT in agent-substrate#1661, the actor JWT contract in agent-substrate#1756), which likely supersedes this provider design, and this fork line has to re-pin past agent-substrate#1809 before it can follow. Kept as a draft so it can resume in place; tracking in giantswarm/giantswarm#38064. |
|
sure |
90dc3ba to
e27ae95
Compare
|
Written by an agent: #145 (a carry of kagent-dev#47) also edits the |
8a25c47 to
85d02ec
Compare
credentialProvider.additionalProviders adds providers to the egress gateway's credentialProviders list beside the bundled kubernetes.io one, on both the HTTPS and the HTTP listener. The gateway dials each with its pod identity and verifies a servicedns.podcert.ate.dev serving certificate. An entry needs uriAuthority and host, cannot replace kubernetes.io and cannot name an authority twice. The default render is unchanged.
uriAuthority must be a lowercase DNS name and host must be <service>.<namespace>.svc:<port>, the name a servicedns serving certificate carries, so a value can neither inject YAML into the gateway config nor name a provider the gateway can never match or verify. The values and README say which client identity the provider must require.
192ce25 to
9b4f838
Compare
|
Written by an agent: merged as #248, which carries these three commits with your authorship onto the line after its re-pin (this branch conflicted with its base). |
Problem
The egress gateway resolves
ate-secret://URIs through a list of credential providers keyed by URI authority, but the chart renders only the bundledk8s.ioone. kagent needs a second provider that answers for the caller of the current turn, so the caller's bearer is injected at egress and never enters the actor (giantswarm/giantswarm#38054).Change
credentialProvider.additionalProvidersadds providers on both egress listeners.uriAuthoritymust be a lowercase DNS name andhostmust be<service>.<namespace>.svc:<port>, the name the provider'sservicedns.podcert.ate.devserving certificate carries; the gateway presents its pod identity, which the provider must require. The bundled provider cannot be replaced and an authority cannot appear twice. The default render is unchanged.