misc: used kube auth whoami

This commit is contained in:
Sheen Capadngan
2025-12-11 00:54:14 +08:00
parent ff9644a14d
commit 4e1cb7e70b
@@ -126,21 +126,25 @@ export const kubernetesResourceFactory: TPamResourceFactory<
async (baseUrl, httpsAgent) => { async (baseUrl, httpsAgent) => {
const { authMethod } = credentials; const { authMethod } = credentials;
if (authMethod === KubernetesAuthMethod.ServiceAccountToken) { if (authMethod === KubernetesAuthMethod.ServiceAccountToken) {
// Validate service account token by making an authenticated API call // Validate service account token using SelfSubjectReview API (whoami)
// This endpoint doesn't require any special permissions from the service account
try { try {
// TODO: is this the best API endpoint to use for validation? await axios.post(
// the SA may not have access to list ns `${baseUrl}/apis/authentication.k8s.io/v1/selfsubjectreviews`,
// maybe we should use a more specific API endpoint? {
// use /apis/authentication.k8s.io/v1/selfsubjectreviews instead? apiVersion: "authentication.k8s.io/v1",
await axios.get(`${baseUrl}/api/v1/namespaces`, { kind: "SelfSubjectReview"
headers: {
"Content-Type": "application/json",
Authorization: `Bearer ${credentials.serviceAccountToken}`
}, },
...(httpsAgent ? { httpsAgent } : {}), {
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT), headers: {
timeout: EXTERNAL_REQUEST_TIMEOUT "Content-Type": "application/json",
}); Authorization: `Bearer ${credentials.serviceAccountToken}`
},
...(httpsAgent ? { httpsAgent } : {}),
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
timeout: EXTERNAL_REQUEST_TIMEOUT
}
);
logger.info("[Kubernetes Resource Factory] Kubernetes service account token authentication successful"); logger.info("[Kubernetes Resource Factory] Kubernetes service account token authentication successful");
} catch (error) { } catch (error) {