Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(tokens): offline validation #6085

Merged

Conversation

jakubdyszkiewicz
Copy link
Contributor

Introduce offline token validation for all types of tokens in the system.
It lets the user provide the public key as a config file and use other systems (including kumactl) to generate tokens without maintaining the connection to kuma cp.

Changes:

  • A lot of new configuration fields like specified in MADR
  • dpserver#auth is deprecated. useTokenPath is renamed.
  • Autoconfigure new fields from the old fields if old fields are set to smooth the migration process.
  • Issuers can be disabled (enabled by default)
  • Validating tokens using Secrets can be disabled (enabled by default)
  • Token Validators take a list of KeyAccessors and they are executed in the order. That means that static public keys take precedence if they are defined.
  • Issuers can be disabled by passing implementations that always returns an error.

This also comes with an interesting feature that now you can have separate DP tokens signing keys for every zone if you want.

Fix #4031

Checklist prior to review

  • Link to relevant issue as well as docs and UI issues --
  • This will not break child repos: it doesn't hardcode values (.e.g "kumahq" as a image registry) and it will work on Windows, system specific functions like syscall.Mkfifo have equivalent implementation on the other OS --
  • Tests (Unit test, E2E tests, manual test on universal and k8s) --
  • Do you need to update UPGRADE.md? --
  • Does it need to be backported according to the backporting policy? -- no
  • Do you need to explicitly set a > Changelog: entry here or add a ci/ label to run fewer/more tests?

Signed-off-by: Jakub Dyszkiewicz <jakub.dyszkiewicz@gmail.com>
@jakubdyszkiewicz jakubdyszkiewicz requested review from a team, Automaat and lukidzi and removed request for a team February 22, 2023 11:27
Copy link
Contributor

@lahabana lahabana left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sweet!

UPGRADE.md Show resolved Hide resolved
pkg/core/bootstrap/autoconfig.go Show resolved Hide resolved
Copy link
Contributor

@lukidzi lukidzi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🎉

Signed-off-by: Jakub Dyszkiewicz <jakub.dyszkiewicz@gmail.com>
…-validation

Signed-off-by: Jakub Dyszkiewicz <jakub.dyszkiewicz@gmail.com>
@jakubdyszkiewicz jakubdyszkiewicz enabled auto-merge (squash) February 27, 2023 10:15
@jakubdyszkiewicz jakubdyszkiewicz merged commit e856a4f into kumahq:master Feb 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Offline signing of tokens
4 participants