Repository navigation
Conversation
Carry gateway-derived endpoint owners through policy and credential delivery. Select grants only from owners that admit the current request, refresh provider snapshots per request, and reject superseded installations before forwarding. Cover persistent routes, overlapping owners, denial, refresh, cache expiry and recovery with focused tests and a Podman regression. Signed-off-by: Shiju <shiju@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
Share admitted endpoints between forwarding and credential authorization. Select grants from the live snapshot without rebuilding a locked map, reuse profile policy construction, and preserve freshness guards when grants are removed. Signed-off-by: Shiju <shiju@nvidia.com>
Sanitize authored owner metadata before composing effective policies, preserve derived owners through proposal approval, and normalize advisor endpoint comparisons. Account for gateway-only owner fields in SDK coverage and schema inventory. Signed-off-by: Shiju <shiju@nvidia.com>
Combine upstream multi-grant selection (one grant per protected header) with admitted-owner filtering. Owner admission filters candidates before specificity ranking and the per-header ambiguity check; revision scoping applies to the selected keys. Port the route-recovery e2e test onto the reworked two-grant fixture, serialize SPIFFE fixture ownership across both tests, and recompute the pinned storage schema fingerprints. Signed-off-by: Shiju <shiju@nvidia.com>
…a snapshot for admission Move the endpoint-bound credential key layout into openshell-core. DynamicCredentialKey encodes the key the gateway builds, and the supervisor reads its endpoint selector, credential identity, and revision-scoped form through the same module instead of parsing tab-separated strings in three places. Revision scoping becomes ProviderCredentialSnapshot::scoped_key. inject_for_admitted_owners now takes the pinned snapshot directly. The L7 admission path never acquires a grant from the live credential map, which production populates only alongside a snapshot. L4 forwarding keeps the selector-only path through inject_if_needed. Both share one acquire-and-rewrite step. Delete two relay tests whose behavior the Rego admission tests already prove. Add a test that grants for different headers are acquired only for admitting owners. Signed-off-by: Shiju <shiju@nvidia.com>
|
@shiju-nv i left some feedback on the original issue, can you take a look and xref w/ the impl? feel free to put it into ready for review once that's done and I can task a review |
Apply endpoint-owned grants after policy and request middleware in REST, GraphQL, JSON-RPC/MCP and inspected plaintext forwarding. Preserve live provider and policy checks through guarded writes, reject missing owner metadata, and reject profiles that cannot inject dynamic HTTP credentials. Cover production stream dispatch, multiple endpoints, failure handling and plaintext ownership with focused regressions. Document upgrade ordering. Closes NVIDIA#3657 Signed-off-by: Shiju <shiju@nvidia.com>
|
Label |
Reject control characters at profile import and key construction. Propagate invalid key errors through gateway environment resolution and reject malformed key layouts before token acquisition while preserving supported legacy keys. Consolidate duplicate relay success tests and share forward-proxy setup without removing ownership, canonicalization, refresh or guarded-write assertions. Document token-grant endpoint authority. Signed-off-by: Shiju <shiju@nvidia.com>
|
@johntmyers Updated #4152 so REST, GraphQL, MCP and JSON-RPC share credential preparation after policy and middleware checks. Ready for review. |
Summary
Dynamic token injection now works when providers share a hostname and port but use different paths, including requests on one persistent connection. Inspected REST, GraphQL, MCP and JSON-RPC requests share credential preparation, so adding another endpoint no longer changes authentication behavior.
Related Issue
Closes #3657
Addresses John Myers’s forwarding and credential-safety requirements, including native GraphQL and MCP/JSON-RPC support.
Changes
tls: skip. Fail closed when a matching grant lacks endpoint ownership metadata; upgrade the gateway before the supervisor. L4-only HTTP forwarding retains its existing selector-based behavior.Testing
Focused macOS verification covers key construction/import/decoding, gateway error propagation, endpoint ownership, native protocol dispatch, canonical paths, failures and credential refresh. The consolidated tests retain exact resolver order and protected-header assertions. Isolated fault checks verify the regressions detect the corrected behavior.
The PR includes a Podman A/B/A regression. Branch Checks and standard runtime E2E passed on the preceding commit; both must rerun for this update. Local duplex-stream tests do not exercise CONNECT negotiation or TLS termination.
Checklist