Skip to content

fix(providers): prepare dynamic credentials across HTTP relay paths - #4152

Open
shiju-nv wants to merge 7 commits into
NVIDIA:mainfrom
shiju-nv:fix/3657-admitted-endpoint/shiju-nv
Open

shiju-nv wants to merge 7 commits into
NVIDIA:mainfrom
shiju-nv:fix/3657-admitted-endpoint/shiju-nv

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Dynamic token injection now works when providers share a hostname and port but use different paths, including requests on one persistent connection. Inspected REST, GraphQL, MCP and JSON-RPC requests share credential preparation, so adding another endpoint no longer changes authentication behavior.

Related Issue

Closes #3657

Addresses John Myers’s forwarding and credential-safety requirements, including native GraphQL and MCP/JSON-RPC support.

Changes

  • Prepare credentials after policy authorization and request middleware, before upstream writes, in single-endpoint, multiple-route and inspected plaintext HTTP forwarding.
  • Select grants by canonical host, port and path, restricted to the endpoint policies that admit the request and calling binary. Recheck ownership after middleware changes the body; reject ambiguous grants and replace protected headers consistently.
  • Read current credentials for each request. Preserve policy generation, provider revision and installation checks through token acquisition and the guarded upstream write. Grant failures send no request bytes upstream.
  • Reject token-grant profiles using SQL or tls: skip. Fail closed when a matching grant lacks endpoint ownership metadata; upgrade the gateway before the supervisor. L4-only HTTP forwarding retains its existing selector-based behavior.
  • Validate dynamic credential key components at profile import and construction, and check decoding before acquisition. Reject control characters instead of misreading credential names. Preserve the existing key format and document endpoint ownership.
  • Add production stream-dispatch regressions and consolidate duplicate success cases while preserving canonical paths, A/B/A ordering and header replacement.

Testing

  • Checks appropriate to the affected code and behavior pass
  • Unit tests added/updated (if applicable)
  • E2E tests added/updated (if applicable)

Focused macOS verification covers key construction/import/decoding, gateway error propagation, endpoint ownership, native protocol dispatch, canonical paths, failures and credential refresh. The consolidated tests retain exact resolver order and protected-header assertions. Isolated fault checks verify the regressions detect the corrected behavior.

The PR includes a Podman A/B/A regression. Branch Checks and standard runtime E2E passed on the preceding commit; both must rerun for this update. Local duplex-stream tests do not exercise CONNECT negotiation or TLS termination.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

Carry gateway-derived endpoint owners through policy and credential delivery. Select grants only from owners that admit the current request, refresh provider snapshots per request, and reject superseded installations before forwarding.

Cover persistent routes, overlapping owners, denial, refresh, cache expiry and recovery with focused tests and a Podman regression.

Signed-off-by: Shiju <shiju@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

Share admitted endpoints between forwarding and credential authorization. Select grants from the live snapshot without rebuilding a locked map, reuse profile policy construction, and preserve freshness guards when grants are removed.

Signed-off-by: Shiju <shiju@nvidia.com>
@shiju-nv
shiju-nv marked this pull request as ready for review October 5, 2026 11:58
@shiju-nv
shiju-nv marked this pull request as draft October 5, 2026 12:19
Sanitize authored owner metadata before composing effective policies, preserve derived owners through proposal approval, and normalize advisor endpoint comparisons. Account for gateway-only owner fields in SDK coverage and schema inventory.

Signed-off-by: Shiju <shiju@nvidia.com>
@shiju-nv shiju-nv changed the title fix(providers): bind multi-route grants to admitted endpoints fix(providers): inject dynamic tokens for multiple paths on one host Oct 5, 2026
Combine upstream multi-grant selection (one grant per protected header) with admitted-owner filtering. Owner admission filters candidates before specificity ranking and the per-header ambiguity check; revision scoping applies to the selected keys. Port the route-recovery e2e test onto the reworked two-grant fixture, serialize SPIFFE fixture ownership across both tests, and recompute the pinned storage schema fingerprints.

Signed-off-by: Shiju <shiju@nvidia.com>
…a snapshot for admission

Move the endpoint-bound credential key layout into openshell-core. DynamicCredentialKey encodes the key the gateway builds, and the supervisor reads its endpoint selector, credential identity, and revision-scoped form through the same module instead of parsing tab-separated strings in three places. Revision scoping becomes ProviderCredentialSnapshot::scoped_key.

inject_for_admitted_owners now takes the pinned snapshot directly. The L7 admission path never acquires a grant from the live credential map, which production populates only alongside a snapshot. L4 forwarding keeps the selector-only path through inject_if_needed. Both share one acquire-and-rewrite step.

Delete two relay tests whose behavior the Rego admission tests already prove. Add a test that grants for different headers are acquired only for admitting owners.

Signed-off-by: Shiju <shiju@nvidia.com>
@johntmyers

Copy link
Copy Markdown
Collaborator

@shiju-nv i left some feedback on the original issue, can you take a look and xref w/ the impl? feel free to put it into ready for review once that's done and I can task a review

Apply endpoint-owned grants after policy and request middleware in REST,
GraphQL, JSON-RPC/MCP and inspected plaintext forwarding. Preserve live
provider and policy checks through guarded writes, reject missing owner
metadata, and reject profiles that cannot inject dynamic HTTP credentials.

Cover production stream dispatch, multiple endpoints, failure handling and
plaintext ownership with focused regressions. Document upgrade ordering.

Closes NVIDIA#3657

Signed-off-by: Shiju <shiju@nvidia.com>
@shiju-nv shiju-nv added the test:e2e Requires end-to-end coverage label Oct 6, 2026
@shiju-nv shiju-nv changed the title fix(providers): inject dynamic tokens for multiple paths on one host fix(providers): prepare dynamic credentials across HTTP relay paths Oct 6, 2026
@shiju-nv
shiju-nv marked this pull request as ready for review October 6, 2026 17:27
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Label test:e2e applied for 6eeb54a. Open Branch E2E Checks, find the run for commit 6eeb54a, and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

Reject control characters at profile import and key construction. Propagate
invalid key errors through gateway environment resolution and reject malformed
key layouts before token acquisition while preserving supported legacy keys.

Consolidate duplicate relay success tests and share forward-proxy setup without
removing ownership, canonicalization, refresh or guarded-write assertions.
Document token-grant endpoint authority.

Signed-off-by: Shiju <shiju@nvidia.com>
@shiju-nv

shiju-nv commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator Author

@johntmyers Updated #4152 so REST, GraphQL, MCP and JSON-RPC share credential preparation after policy and middleware checks. Ready for review.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

RFE: support dynamic credential injection for multiple provider paths on the same hostname

2 participants