Skip to content

localjwtauthority: thumbprint key IDs and a configurable signing algorithm - #1961

Merged
Eitan Yarmush (EItanya) merged 4 commits into
agent-substrate:mainfrom
thompsonmax:actor-jwt-rs256-thumbprint
Oct 6, 2026
Merged

Eitan Yarmush (EItanya) merged 4 commits into
agent-substrate:mainfrom
thompsonmax:actor-jwt-rs256-thumbprint

Conversation

@thompsonmax

@thompsonmax Max Thompson (thompsonmax) commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Part of #1756.

  • Adds oidcdiscovery.Thumbprint, which computes the RFC 7638 SHA-256 thumbprint of an RSA or P-256 key with go-jose, so key IDs come from the key instead of being picked by hand.
  • Replaces GenerateECDSAP256Authority with GenerateAuthority(algorithm, id), which generates an ES256 or RS256 (2048-bit) key and defaults the ID to the thumbprint.
  • kubectl ate admin make-jwt-pool gains --alg (default ES256), and --key-id now defaults to the thumbprint. ate-setup reads the algorithm from ACTOR_JWT_ALGORITHM, so an install whose relying parties don't support ES256 can choose RS256.

Existing pools keep their key and ID 1; only newly created pools get a thumbprint ID. go-jose moves from an indirect to a direct dependency in go.mod; it was already vendored, so vendor/ is unchanged.

Testing: unit tests for the thumbprint (including the RFC 7638 example key), key generation, both pool builders, and the new setting. E2E hasn't run locally.

  • Tests pass
  • Appropriate changes to documentation are included in the PR

@bowei Bowei Du (bowei) added area/cli area/dev-infra area/identity kind/feature An enhancement / feature request or implementation labels Sep 30, 2026
@thompsonmax
Max Thompson (thompsonmax) marked this pull request as ready for review September 30, 2026 22:16
@thompsonmax
Max Thompson (thompsonmax) marked this pull request as draft October 1, 2026 17:36
@thompsonmax Max Thompson (thompsonmax) changed the title localjwtauthority: default new keys to RS256 with thumbprint key IDs localjwtauthority: thumbprint key IDs and a configurable signing algorithm Oct 1, 2026
@thompsonmax
Max Thompson (thompsonmax) marked this pull request as ready for review October 1, 2026 17:49
@thompsonmax
Max Thompson (thompsonmax) force-pushed the actor-jwt-rs256-thumbprint branch 2 times, most recently from dfc6ebe to fd5fc1e Compare October 1, 2026 22:34
Taahir Ahmed (ahmedtd) pushed a commit to ahmedtd/substrate that referenced this pull request Oct 2, 2026
…requests race (agent-substrate#2095)

The egress gateway's policy cache checks for a cached entry and then
joins any in-flight fetch, and the two steps aren't atomic. If the
in-flight fetch stores its result in between, the caller starts a
second, redundant fetch from ateapi.
`TestPolicyCacheFetchOutlivesCanceledCaller` asserts a single fetch, so
it fails intermittently (about 1 in 300 runs under `-race`; seen on
agent-substrate#1961).

- Re-checks the cache at the start of the shared fetch, so a late caller
reuses the entry that just landed instead of fetching again.
- Moves the cache lookup into a `cached` helper that both the fast path
and the shared fetch use.

The only behavior change is skipping the duplicate fetch.

Testing: with the fix, the existing test passed 2000 of 2000 runs under
`-race`. E2E hasn't run locally.

- [ ] Tests pass
- [ ] Appropriate changes to documentation are included in the PR

@EItanya Eitan Yarmush (EItanya) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 AI-generated review.

A couple of optional simplification suggestions.

Comment thread cmd/kubectl-ate/internal/cmd/admin.go Outdated
Comment thread go.mod
Add oidcdiscovery.Thumbprint, the RFC 7638 SHA-256 thumbprint of an RSA
or P-256 public key, and replace GenerateECDSAP256Authority with
GenerateAuthority, which generates an RS256 or ES256 key and defaults
its ID to the thumbprint. A thumbprint ID cannot collide across
operators or be reused for a different key.

kubectl ate admin make-jwt-pool gains --alg, defaulting to RS256, and
--key-id now defaults to the thumbprint. ate-setup creates the same kind
of pool. RS256 works with relying parties that do not support ES256.

Existing pools are untouched, so keys named "1" keep working.
New actor JWT pools default to ES256 again, matching every existing
pool. make-jwt-pool --alg defaults to ES256, and ate-setup reads the
algorithm from ACTOR_JWT_ALGORITHM (ES256 or RS256, default ES256), so
an install whose relying parties do not support ES256 can choose RS256
without creating the pool by hand. Key IDs still default to the
thumbprint.
Use go-jose's JSONWebKey.Thumbprint instead of building the RFC 7638
canonical form by hand. Thumbprint still accepts only RSA and P-256
keys, the types the pool generates. go-jose moves from an indirect to a
direct dependency; it was already vendored.
kubectl-ate's make-jwt-pool and ate-setup each generated an authority,
made it active, and marshaled the pool. GeneratePool does that and
returns the serialized pool and the authority's ID, so both callers only
build their Secret.
@EItanya
Eitan Yarmush (EItanya) added this pull request to the merge queue Oct 5, 2026
Merged via the queue into agent-substrate:main with commit 2b5dcb3 Oct 6, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/cli area/dev-infra area/identity kind/feature An enhancement / feature request or implementation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants