Repository navigation
egress policy: add an actor JWT value source to CredentialHeader - #1960
Merged
Eitan Yarmush (EItanya) merged 1 commit intoOct 1, 2026
Merged
Eitan Yarmush (EItanya) merged 1 commit into
Eitan Yarmush (EItanya) merged 1 commit into
Conversation
Max Thompson (thompsonmax)
force-pushed
the
actor-jwt-source-api
branch
from
September 28, 2026 22:03
317a19b to
e22503e
Compare
Max Thompson (thompsonmax)
marked this pull request as ready for review
September 28, 2026 22:17
Max Thompson (thompsonmax)
requested review from
Lior Lieberman (LiorLieberman) and
Taahir Ahmed (ahmedtd)
September 28, 2026 22:17
Max Thompson (thompsonmax)
requested review from
Eitan Yarmush (EItanya) and
Taahir Ahmed (ahmedtd)
September 30, 2026 21:32
Eitan Yarmush (EItanya)
previously approved these changes
Sep 30, 2026
Eitan Yarmush (EItanya)
left a comment
Collaborator
There was a problem hiding this comment.
Api looks much better
Max Thompson (thompsonmax)
force-pushed
the
actor-jwt-source-api
branch
from
September 30, 2026 22:53
669747b to
ed45314
Compare
Eitan Yarmush (EItanya)
previously approved these changes
Sep 30, 2026
Eitan Yarmush (EItanya)
enabled auto-merge
September 30, 2026 22:54
github-merge-queue
Bot
removed this pull request from the merge queue due to a conflict with the base branch
Sep 30, 2026
Add ActorJWTSource as a second value source for a replace_headers entry, next to credential_uri, so an EgressPolicy can have the egress gateway replace a header with a Substrate-issued JWT for the actor that sent the request. The two fields form a union and exactly one must be set. credential_uri stays a plain string: an empty credential URI is never valid, so the union treats the empty string as unset, and every stored policy stays valid. ActorJWTSource names the audiences the JWT is bound to and its lifetime, which is required and bounded to 300 to 3600 seconds, so the policy author always chooses how long the gateway's JWTs live. The gateway cannot mint actor JWTs yet. Until it can, an https rule that asks for one denies the request with 501 instead of failing on the empty credential URI. Actor JWTs do not come from the credential provider, so the denial applies even when no provider is configured. Like a credential_uri entry, an actor JWT entry is skipped on http rules.
Max Thompson (thompsonmax)
force-pushed
the
actor-jwt-source-api
branch
from
October 1, 2026 00:28
ed45314 to
2439330
Compare
Eitan Yarmush (EItanya)
approved these changes
Oct 1, 2026
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1660.
CredentialHeader.actor_jwt(ActorJWTSource), a union member alongsidecredential_uri, so areplace_headersentry can carry a Substrate-issued actor JWT instead of a provider secret.ActorJWTSourcetakes the token'saudiencesand a requiredexpiration_secondsin [300, 3600], matchingMintActorJWTRequest(ateapi: require an actor JWT lifetime and align the subject with the SPIFFE ID #1902).httpsrule with anactor_jwtentry with 501. Likecredential_urientries,actor_jwtentries are skipped onhttprules.Testing: unit tests for validation and the gateway's 501 on
httpsand skip onhttp. The functional tests need Docker, so they haven't run locally.