Skip to content

AuthBridge webhook does not emit spiffe block in per-agent ConfigMap #467

Description

@r3v5

Bug

The AuthBridge mutating webhook's ensurePerAgentConfigMap does not write the spiffe block into per-agent ConfigMaps when spireEnabled=true, causing authbridge-proxy to crash with:

time=2026-06-23T15:39:54.635Z level=INFO msg="mtls requires the spiffe block to be configured"

Expected

When spireEnabled=true (confirmed by webhook logs: "injection decision","sidecar":"spiffe-helper","inject":true), the per-agent ConfigMap should contain:

spiffe:
  socket: unix:///spiffe-workload-api/spire-agent.sock

Actual

The per-agent ConfigMap (authbridge-config-<agent-name>) has mtls.mode: permissive but no spiffe block. AuthBridge requires the spiffe block when mTLS is enabled.

Root Cause

Code at internal/webhook/injector/pod_mutator.go:988-991 sets cfg["spiffe"] when spireEnabled=true:

if spireEnabled {
    cfg["spiffe"] = map[string]interface{}{
        "socket": m.GetPlatformConfig().Spiffe.SocketPath,
    }
}

However, the produced ConfigMap does not contain this block. The webhook logs confirm spireEnabled=true but the serialized YAML written to the ConfigMap omits the spiffe key.

Workaround

Manually patch the per-agent ConfigMap after pod creation:

# Get current config
oc -n <namespace> get configmap authbridge-config-<agent-name> -o jsonpath='{.data.config\.yaml}' > /tmp/config.yaml

# Append spiffe block
cat >> /tmp/config.yaml << 'SPIFFE'
spiffe:
  socket: unix:///spiffe-workload-api/spire-agent.sock
SPIFFE

# Apply
oc -n <namespace> create configmap authbridge-config-<agent-name> \
  --from-file=config.yaml=/tmp/config.yaml --dry-run=client -o yaml | oc apply -f -

AuthBridge's built-in config reloader picks up the change on next CrashLoopBackOff restart.

Environment

  • OCP (ROSA) 4.19.18
  • kagenti-operator image built from branch create-controller-for-spire-and-ztwim
  • AuthBridge image: ghcr.io/kagenti/kagenti-extensions/authbridge:latest
  • mTLS mode: permissive
  • SPIRE trust domain: localtest.me

Impact

All A2A agents with mTLS enabled have authbridge-proxy in CrashLoopBackOff until the ConfigMap is manually patched.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status
    New/ToDo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions