Skip to content

v0.4.0 — Gateway authentication

Choose a tag to compare

@chitrangpatel chitrangpatel released this 20 May 01:09
· 20 commits to main since this release

What's new

Gateway authentication support

Instrument now accepts two optional parameters for authenticating with the HelixObs gateway:

tel = CHIMEInstrument(
    service_name="chime-frb-pipeline",
    instrument_id="CHIMEFRB",
    endpoint="206-12-91-148.cloud.computecanada.ca:4317",
    credential=os.environ["CHIMEFRB_ACCESS_TOKEN"],
    auth_endpoint="https://206-12-91-148.cloud.computecanada.ca/auth/token",
)
  • credential — registration secret or existing instrument JWT (e.g. CHIMEFRB_ACCESS_TOKEN)
  • auth_endpoint — URL of the gateway POST /auth/token endpoint

The client exchanges the credential for a short-lived HelixObs JWT at startup and attaches it to every OTLP export. Token refresh is automatic (1 hour before expiry) and thread-safe.

Phase 1 (current — plaintext gRPC)

Pass insecure=True (the default). The JWT is embedded as a static header at exporter creation. Valid for 24 hours; restart the process to refresh after expiry.

Phase 2 (future — TLS gRPC)

Pass insecure=False. A gRPC AuthMetadataPlugin refreshes the token per-RPC without recreating the channel.

Upgrading

No breaking changes. The new parameters are optional — existing code without credential/auth_endpoint continues to work unchanged. Auth enforcement on the gateway side is gated by the JWT_SECRET env var (empty = disabled).