Skip to content

egress policy: add an actor JWT value source to CredentialHeader - #1960

Merged
Eitan Yarmush (EItanya) merged 1 commit into
agent-substrate:mainfrom
thompsonmax:actor-jwt-source-api
Oct 1, 2026
Merged

Eitan Yarmush (EItanya) merged 1 commit into
agent-substrate:mainfrom
thompsonmax:actor-jwt-source-api

Conversation

@thompsonmax

@thompsonmax Max Thompson (thompsonmax) commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Part of #1660.

  • Adds CredentialHeader.actor_jwt (ActorJWTSource), a union member alongside credential_uri, so a replace_headers entry can carry a Substrate-issued actor JWT instead of a provider secret.
  • ActorJWTSource takes the token's audiences and a required expiration_seconds in [300, 3600], matching MintActorJWTRequest (ateapi: require an actor JWT lifetime and align the subject with the SPIFFE ID #1902).
  • Until the gateway can mint tokens, it denies an https rule with an actor_jwt entry with 501. Like credential_uri entries, actor_jwt entries are skipped on http rules.

Testing: unit tests for validation and the gateway's 501 on https and skip on http. The functional tests need Docker, so they haven't run locally.

Comment thread pkg/proto/ateapipb/ateapi.proto
Comment thread pkg/proto/ateapipb/ateapi.proto
Comment thread pkg/proto/ateapipb/ateapi.proto Outdated
Comment thread cmd/atenet/internal/router/egress/credentials.go Outdated
@mayawang Maya Wang (mayawang) added area/identity area/network kind/feature An enhancement / feature request or implementation labels Sep 29, 2026
Comment thread pkg/proto/ateapipb/ateapi.proto
Comment thread cmd/ateapi/internal/defaults/defaults.go Outdated

@EItanya Eitan Yarmush (EItanya) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Api looks much better

@EItanya
Eitan Yarmush (EItanya) added this pull request to the merge queue Sep 30, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 30, 2026
Add ActorJWTSource as a second value source for a replace_headers entry,
next to credential_uri, so an EgressPolicy can have the egress gateway
replace a header with a Substrate-issued JWT for the actor that sent the
request. The two fields form a union and exactly one must be set.
credential_uri stays a plain string: an empty credential URI is never
valid, so the union treats the empty string as unset, and every stored
policy stays valid.

ActorJWTSource names the audiences the JWT is bound to and its lifetime,
which is required and bounded to 300 to 3600 seconds, so the policy
author always chooses how long the gateway's JWTs live.

The gateway cannot mint actor JWTs yet. Until it can, an https rule that
asks for one denies the request with 501 instead of failing on the empty
credential URI. Actor JWTs do not come from the credential provider, so
the denial applies even when no provider is configured. Like a
credential_uri entry, an actor JWT entry is skipped on http rules.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/identity area/network kind/feature An enhancement / feature request or implementation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants