mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 09:26:47 +00:00
misc: used kube auth whoami
This commit is contained in:
@@ -126,21 +126,25 @@ export const kubernetesResourceFactory: TPamResourceFactory<
|
|||||||
async (baseUrl, httpsAgent) => {
|
async (baseUrl, httpsAgent) => {
|
||||||
const { authMethod } = credentials;
|
const { authMethod } = credentials;
|
||||||
if (authMethod === KubernetesAuthMethod.ServiceAccountToken) {
|
if (authMethod === KubernetesAuthMethod.ServiceAccountToken) {
|
||||||
// Validate service account token by making an authenticated API call
|
// Validate service account token using SelfSubjectReview API (whoami)
|
||||||
|
// This endpoint doesn't require any special permissions from the service account
|
||||||
try {
|
try {
|
||||||
// TODO: is this the best API endpoint to use for validation?
|
await axios.post(
|
||||||
// the SA may not have access to list ns
|
`${baseUrl}/apis/authentication.k8s.io/v1/selfsubjectreviews`,
|
||||||
// maybe we should use a more specific API endpoint?
|
{
|
||||||
// use /apis/authentication.k8s.io/v1/selfsubjectreviews instead?
|
apiVersion: "authentication.k8s.io/v1",
|
||||||
await axios.get(`${baseUrl}/api/v1/namespaces`, {
|
kind: "SelfSubjectReview"
|
||||||
headers: {
|
|
||||||
"Content-Type": "application/json",
|
|
||||||
Authorization: `Bearer ${credentials.serviceAccountToken}`
|
|
||||||
},
|
},
|
||||||
...(httpsAgent ? { httpsAgent } : {}),
|
{
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
headers: {
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT
|
"Content-Type": "application/json",
|
||||||
});
|
Authorization: `Bearer ${credentials.serviceAccountToken}`
|
||||||
|
},
|
||||||
|
...(httpsAgent ? { httpsAgent } : {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
logger.info("[Kubernetes Resource Factory] Kubernetes service account token authentication successful");
|
logger.info("[Kubernetes Resource Factory] Kubernetes service account token authentication successful");
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
|||||||
Reference in New Issue
Block a user