Repository navigation
Add ate-idp-server to serve the discovery document and key set for actor JWTs - #2099
Open
Max Thompson (thompsonmax) wants to merge 4 commits into
Open
Max Thompson (thompsonmax) wants to merge 4 commits into
Max Thompson (thompsonmax) wants to merge 4 commits into
Conversation
Max Thompson (thompsonmax)
force-pushed
the
ate-idp-server
branch
2 times, most recently
from
October 2, 2026 17:47
4cd8539 to
55d3488
Compare
Max Thompson (thompsonmax)
requested review from
Eitan Yarmush (EItanya),
Shruti Nair (SHRUTI6991) and
Taahir Ahmed (ahmedtd)
October 2, 2026 17:50
Max Thompson (thompsonmax)
marked this pull request as ready for review
October 2, 2026 17:50
2 tasks done
Max Thompson (thompsonmax)
force-pushed
the
ate-idp-server
branch
from
October 5, 2026 22:59
55d3488 to
f8da78f
Compare
2 tasks
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
Add JWKS, which serializes verification keys into the JWK set relying parties fetch from the issuer, sorted by key ID. It encodes with go-jose's JSONWebKey, as the Kubernetes service account issuer does, and adds the checks go-jose leaves to the caller: the set is not empty, key IDs are present and unique, and each algorithm fits its key (ES256 for P-256 EC, RS256, RS384, or RS512 for RSA), so a malformed pool cannot publish a set that verifiers would reject. localjwtauthority.VerificationKey gains Algorithm so callers can publish it.
Max Thompson (thompsonmax)
force-pushed
the
ate-idp-server
branch
from
October 6, 2026 16:14
f8da78f to
6856a5e
Compare
The rest of Substrate's JWT code is in-tree, and go-jose was only used here, for RFC 7638 thumbprints and JWK encoding. Thumbprint is now the base64url SHA-256 of the key's PKIX (SubjectPublicKeyInfo) DER encoding. Key IDs are opaque to relying parties, and pools store each key's ID, so existing keys keep theirs; only new keys get IDs in the new form. JWKS encodes RSA and P-256 keys itself, with the RFC 7518 parameters, padding EC coordinates to the curve size. go-jose stays in go.mod only as an indirect dependency of go-spiffe.
Add a small read-only HTTPS server for the OpenID discovery document and JWK set that relying parties use to verify actor JWTs. It serves the key set from --jwks-file as is, builds the discovery document from the keys' algorithms with oidcdiscovery.DiscoveryDocument, and reloads when the file changes, keeping the last good set if a new one does not parse. Routes sit under the issuer's path and match on the cleaned path. --issuer is required. The installer passes the same value it gives ateapi, so the two cannot derive different issuers. Until a key set loads, /readyz and both documents return 503, so a relying party never caches an empty set. TLS uses the servicedns credential bundle through credbundle, which picks up rotated certificates. The server emits no metrics, which docs/metrics/substrate.yaml records.
ate-idp-server read a JWK set that a controller was to derive from the authority pool and copy into a ConfigMap. It now mounts the pool itself and reads it with localjwtauthority.RefreshingPool, the same reader ate-api-server signs with, so publishing a key needs no second component and no internal ConfigMap. --actor-id-jwt-pool replaces --jwks-file and --reload-interval; the pool is reread at most once a minute. Each request builds the key set and discovery document from the pool's verification keys. RefreshingPool fails every call after a bad reread, so the server keeps the last documents it built and serves those; until it has built any, it reports not ready and answers with 503.
Max Thompson (thompsonmax)
force-pushed
the
ate-idp-server
branch
from
October 6, 2026 17:06
6856a5e to
8536af6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1756. Stacked on #2132; only the last two commits are new.
cmd/ate-idp-server, which serves<issuer>/.well-known/openid-configurationand<issuer>/openid/v1/jwksover HTTPS with a servicedns credential bundle, so relying parties can verify actor JWTs.--actor-id-jwt-poolwithlocaljwtauthority.RefreshingPool, the reader ate-api-server signs with, and builds both documents from the pool's verification keys on each request.--issuerrather than deriving a default, so it can't disagree with ateapi; the installer will pass both the same value.docs/metrics/substrate.yamlthat it emits no metrics.For reviewers: the pool holds the signing keys, so ate-idp-server will mount the same Secret ate-api-server does, in place of the controller and ConfigMap in #2134. Nothing deploys it yet.
Testing: unit tests for routing (including issuer paths and dot segments), headers, readiness, key changes, last-good serving, and required flags, plus a local run over TLS against a generated pool. E2E can't cover it until it's deployed.