Skip to content

Fix TokenVendor IAM impersonation chain#626

Merged
rastislav-vcrs merged 2 commits intomainfrom
rko-tv-actas
Feb 20, 2026
Merged

Fix TokenVendor IAM impersonation chain#626
rastislav-vcrs merged 2 commits intomainfrom
rko-tv-actas

Conversation

@rastislav-vcrs
Copy link
Contributor

This change fixes the issue where token vendor would attempt to impersonate service accounts without building a proper chain of delegates. It also enforces that the chain to impersonate alternative service account requires proper permissions on the full chain of token-vendor, robot-service, SA to impersonate.

Copy link
Contributor

@ensonic ensonic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

This change fixes the issue where token vendor would attempt
to impersonate service accounts without building a proper
chain of delegates. It also enforces that the chain to impersonate
alternative service account requires proper permissions on the
full chain of token-vendor, robot-service, SA to impersonate.
@rastislav-vcrs rastislav-vcrs merged commit d6da2cc into main Feb 20, 2026
7 checks passed
@rastislav-vcrs rastislav-vcrs deleted the rko-tv-actas branch February 20, 2026 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants