Repository navigation
v0.54.0
The egress credential-substitution engine is now a shared package, so a
second front door can be built on the same core, and the host allow-list rule
it scopes secrets by is its own package.
Added
egress: credential substitution at an egress boundary. A workload holds
an opaque placeholder (MintPlaceholder,IsPlaceholder); the engine
(Map,NewMap,Map.SubstituteValue,Map.HostHasSecret,
SubstituteHTTPRequest) swaps it for the real secret only toward the hosts
the credential is scoped to.Registryholds one map per principal;
IngestHandlerandDecodeIngestBodyfill it over the control-plane API,
andClientis the matching caller with per-replica fan-out
(PushMapAllReplicas,PurgeMapAllReplicas).RePusherkeeps every
replica warm from aPrincipalLister,PlaceholderReader,
SecretResolver, andMapPusher.TokenAuthverifies the proxy JWT
against a JWKS withTokenAuthOptions: the requiredAudience, an optional
ScopeandKind, andSubjectClaim, the claim that names the principal
(defaultsub).Gatewayis the TLS-terminating CONNECT proxy on top,
withRealmfor its 407 challenge, andCAmints the per-SNI leaves
(GenerateCA(commonName),LoadCA,CA.CertPEM). Every piece below
Gatewayworks without it.hostmatch: the one host allow-list rule every egress surface shares.
New(patterns, normalize)compiles exact FQDNs and*.-prefixed wildcards
into aMatcher;ValidPatternis the grammar.