v0.4.0 — Gateway authentication
What's new
Gateway authentication support
Instrument now accepts two optional parameters for authenticating with the HelixObs gateway:
tel = CHIMEInstrument(
service_name="chime-frb-pipeline",
instrument_id="CHIMEFRB",
endpoint="206-12-91-148.cloud.computecanada.ca:4317",
credential=os.environ["CHIMEFRB_ACCESS_TOKEN"],
auth_endpoint="https://206-12-91-148.cloud.computecanada.ca/auth/token",
)credential— registration secret or existing instrument JWT (e.g.CHIMEFRB_ACCESS_TOKEN)auth_endpoint— URL of the gatewayPOST /auth/tokenendpoint
The client exchanges the credential for a short-lived HelixObs JWT at startup and attaches it to every OTLP export. Token refresh is automatic (1 hour before expiry) and thread-safe.
Phase 1 (current — plaintext gRPC)
Pass insecure=True (the default). The JWT is embedded as a static header at exporter creation. Valid for 24 hours; restart the process to refresh after expiry.
Phase 2 (future — TLS gRPC)
Pass insecure=False. A gRPC AuthMetadataPlugin refreshes the token per-RPC without recreating the channel.
Upgrading
No breaking changes. The new parameters are optional — existing code without credential/auth_endpoint continues to work unchanged. Auth enforcement on the gateway side is gated by the JWT_SECRET env var (empty = disabled).