Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
STACKIT servers can have service accounts attached, either on creation (
--service-account-emails) or later through the IaaS API. Code running on such a server can then obtain short-lived tokens for accounts via the IaaS-API. The SDK has no flow for this today, so applications on STACKIT servers have to implement the token fetch, caching and refresh themselves.This PR adds a metadata flow next to the key, token and workload identity federation flows:
config.WithMetadataAuth()enables it explicitly; the account comes fromconfig.WithServiceAccountEmail(...)orSTACKIT_SERVICE_ACCOUNT_EMAIL, as for workload identity federation.clients.MetadataFlowfetchesGET http://169.254.169.254/stackit/v1/service-accounts/<email>/token, caches the token until itsvalidUntiland refreshes it 5 minutes early; background refresh viaWithBackgroundTokenRefreshworks as for the other flows.404is reported as the account not being attached to the server.DefaultAuth, so clients outside a STACKIT server never wait on the link-local address.The token endpoint's response is not documented, so it was measured on a server in eu01 with a service account attached: it answers exactly
{"token", "validUntil"}, the token is an RS256 JWT valid for one hour withexpequal tovalidUntil, and every request mints a new token. Hence the caching and the 5-minute refresh margin.Checklist
make fmtexamples/directory)make test(will be checked by CI)make lint(will be checked by CI)