Skip to content

feat(core): support metadata flow for the service account attached tothe server - #12521

Open
tank-bohr wants to merge 1 commit into
stackitcloud:mainfrom
tank-bohr:feat/metadata-auth-flow
Open

tank-bohr wants to merge 1 commit into
stackitcloud:mainfrom
tank-bohr:feat/metadata-auth-flow

Conversation

@tank-bohr

@tank-bohr tank-bohr commented Oct 5, 2026 •

Copy link
Copy Markdown

Description

STACKIT servers can have service accounts attached, either on creation (--service-account-emails) or later through the IaaS API. Code running on such a server can then obtain short-lived tokens for accounts via the IaaS-API. The SDK has no flow for this today, so applications on STACKIT servers have to implement the token fetch, caching and refresh themselves.

This PR adds a metadata flow next to the key, token and workload identity federation flows:

  • config.WithMetadataAuth() enables it explicitly; the account comes from config.WithServiceAccountEmail(...) or STACKIT_SERVICE_ACCOUNT_EMAIL, as for workload identity federation.
  • clients.MetadataFlow fetches GET http://169.254.169.254/stackit/v1/service-accounts/<email>/token, caches the token until its validUntil and refreshes it 5 minutes early; background refresh via WithBackgroundTokenRefresh works as for the other flows.
  • Requests to the metadata service never go through a proxy; a 404 is reported as the account not being attached to the server.
  • The flow is not part of DefaultAuth, so clients outside a STACKIT server never wait on the link-local address.

The token endpoint's response is not documented, so it was measured on a server in eu01 with a service account attached: it answers exactly {"token", "validUntil"}, the token is an RS256 JWT valid for one hour with exp equal to validUntil, and every request mints a new token. Hence the caching and the 5-minute refresh margin.

Checklist

  • Issue was linked above
  • No generated code was adjusted manually (check comments in file header)
  • Changelogs
    • Changelog in the root directory was adjusted (see here)
    • [x ] Changelog(s) of the service(s) were adjusted (see e.g. here)
  • VERSION file(s) of the service(s) were adjusted
  • Code format was applied: make fmt
  • Examples were added / adjusted (see examples/ directory)
  • Unit tests got implemented or updated
  • Unit tests are passing: make test (will be checked by CI)
  • No linter issues: make lint (will be checked by CI)

@tank-bohr
tank-bohr requested a review from a team as a code owner October 5, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant