localjwtauthority: thumbprint key IDs and a configurable signing algorithm - #1961
Merged
Eitan Yarmush (EItanya) merged 4 commits intoOct 6, 2026
Conversation
Max Thompson (thompsonmax)
marked this pull request as ready for review
September 30, 2026 22:16
Max Thompson (thompsonmax)
marked this pull request as draft
October 1, 2026 17:36
Max Thompson (thompsonmax)
marked this pull request as ready for review
October 1, 2026 17:49
Max Thompson (thompsonmax)
force-pushed
the
actor-jwt-rs256-thumbprint
branch
from
October 1, 2026 17:51
7caeb5a to
89d315b
Compare
Max Thompson (thompsonmax)
requested review from
Eitan Yarmush (EItanya) and
Shruti Nair (SHRUTI6991)
October 1, 2026 18:45
Max Thompson (thompsonmax)
force-pushed
the
actor-jwt-rs256-thumbprint
branch
2 times, most recently
from
October 1, 2026 22:34
dfc6ebe to
fd5fc1e
Compare
2 tasks
Taahir Ahmed (ahmedtd)
pushed a commit
to ahmedtd/substrate
that referenced
this pull request
Oct 2, 2026
…requests race (agent-substrate#2095) The egress gateway's policy cache checks for a cached entry and then joins any in-flight fetch, and the two steps aren't atomic. If the in-flight fetch stores its result in between, the caller starts a second, redundant fetch from ateapi. `TestPolicyCacheFetchOutlivesCanceledCaller` asserts a single fetch, so it fails intermittently (about 1 in 300 runs under `-race`; seen on agent-substrate#1961). - Re-checks the cache at the start of the shared fetch, so a late caller reuses the entry that just landed instead of fetching again. - Moves the cache lookup into a `cached` helper that both the fast path and the shared fetch use. The only behavior change is skipping the duplicate fetch. Testing: with the fix, the existing test passed 2000 of 2000 runs under `-race`. E2E hasn't run locally. - [ ] Tests pass - [ ] Appropriate changes to documentation are included in the PR
2 tasks
Max Thompson (thompsonmax)
force-pushed
the
actor-jwt-rs256-thumbprint
branch
from
October 2, 2026 18:24
c8fe182 to
f0d83f8
Compare
This was referenced Oct 2, 2026
Max Thompson (thompsonmax)
force-pushed
the
actor-jwt-rs256-thumbprint
branch
from
October 2, 2026 22:32
f0d83f8 to
1621f67
Compare
Eitan Yarmush (EItanya)
left a comment
Collaborator
There was a problem hiding this comment.
🤖 AI-generated review.
A couple of optional simplification suggestions.
Add oidcdiscovery.Thumbprint, the RFC 7638 SHA-256 thumbprint of an RSA or P-256 public key, and replace GenerateECDSAP256Authority with GenerateAuthority, which generates an RS256 or ES256 key and defaults its ID to the thumbprint. A thumbprint ID cannot collide across operators or be reused for a different key. kubectl ate admin make-jwt-pool gains --alg, defaulting to RS256, and --key-id now defaults to the thumbprint. ate-setup creates the same kind of pool. RS256 works with relying parties that do not support ES256. Existing pools are untouched, so keys named "1" keep working.
New actor JWT pools default to ES256 again, matching every existing pool. make-jwt-pool --alg defaults to ES256, and ate-setup reads the algorithm from ACTOR_JWT_ALGORITHM (ES256 or RS256, default ES256), so an install whose relying parties do not support ES256 can choose RS256 without creating the pool by hand. Key IDs still default to the thumbprint.
Use go-jose's JSONWebKey.Thumbprint instead of building the RFC 7638 canonical form by hand. Thumbprint still accepts only RSA and P-256 keys, the types the pool generates. go-jose moves from an indirect to a direct dependency; it was already vendored.
kubectl-ate's make-jwt-pool and ate-setup each generated an authority, made it active, and marshaled the pool. GeneratePool does that and returns the serialized pool and the authority's ID, so both callers only build their Secret.
Max Thompson (thompsonmax)
force-pushed
the
actor-jwt-rs256-thumbprint
branch
from
October 5, 2026 17:42
6842954 to
0256cf8
Compare
Eitan Yarmush (EItanya)
approved these changes
Oct 5, 2026
2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1756.
oidcdiscovery.Thumbprint, which computes the RFC 7638 SHA-256 thumbprint of an RSA or P-256 key with go-jose, so key IDs come from the key instead of being picked by hand.GenerateECDSAP256AuthoritywithGenerateAuthority(algorithm, id), which generates an ES256 or RS256 (2048-bit) key and defaults the ID to the thumbprint.kubectl ate admin make-jwt-poolgains--alg(default ES256), and--key-idnow defaults to the thumbprint.ate-setupreads the algorithm fromACTOR_JWT_ALGORITHM, so an install whose relying parties don't support ES256 can choose RS256.Existing pools keep their key and ID
1; only newly created pools get a thumbprint ID. go-jose moves from an indirect to a direct dependency ingo.mod; it was already vendored, sovendor/is unchanged.Testing: unit tests for the thumbprint (including the RFC 7638 example key), key generation, both pool builders, and the new setting. E2E hasn't run locally.