You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit ed45314
Browse filesBrowse the repository at this point in the historyBrowse files
egress policy: add an actor JWT value source to CredentialHeader
Add ActorJWTSource as a second value source for a replace_headers entry,
next to credential_uri, so an EgressPolicy can have the egress gateway
replace a header with a Substrate-issued JWT for the actor that sent the
request. The two fields form a union and exactly one must be set.
credential_uri stays a plain string: an empty credential URI is never
valid, so the union treats the empty string as unset, and every stored
policy stays valid.
ActorJWTSource names the audiences the JWT is bound to and its lifetime,
which is required and bounded to 300 to 3600 seconds, so the policy
author always chooses how long the gateway's JWTs live.
The gateway cannot mint actor JWTs yet. Until it can, an https rule that
asks for one denies the request with 501 instead of failing on the empty
credential URI. Actor JWTs do not come from the credential provider, so
the denial applies even when no provider is configured. Like a
credential_uri entry, an actor JWT entry is skipped on http rules.
field.Invalid(staticHeader.Child("credential_uri"), "https://example.com/secret", "must be ate-secret://<provider-class>/<provider-name>/<provider-specific-tail>"),
slog.WarnContext(ctx, "egress: skipping credential injection because no credential provider is configured; the request proceeds without the credential",
0 commit comments