Merge pull request #3752 from akhilmhdh/feat/k8s-metadata-auth

feat: added k8s metadata in template policy
This commit is contained in:
Maidul Islam
2025-06-06 15:30:33 -04:00
committed by GitHub
6 changed files with 38 additions and 6 deletions
+4
View File
@@ -119,6 +119,10 @@ declare module "@fastify/request-context" {
oidc?: { oidc?: {
claims: Record<string, string>; claims: Record<string, string>;
}; };
kubernetes?: {
namespace: string;
name: string;
};
}; };
identityPermissionMetadata?: Record<string, unknown>; // filled by permission service identityPermissionMetadata?: Record<string, unknown>; // filled by permission service
assumedPrivilegeDetails?: { requesterId: string; actorId: string; actorType: ActorType; projectId: string }; assumedPrivilegeDetails?: { requesterId: string; actorId: string; actorType: ActorType; projectId: string };
@@ -155,6 +155,12 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
oidc: token?.identityAuth?.oidc oidc: token?.identityAuth?.oidc
}); });
} }
if (token?.identityAuth?.kubernetes) {
requestContext.set("identityAuthInfo", {
identityId: identity.identityId,
kubernetes: token?.identityAuth?.kubernetes
});
}
break; break;
} }
case AuthMode.SERVICE_TOKEN: { case AuthMode.SERVICE_TOKEN: {
@@ -11,5 +11,9 @@ export type TIdentityAccessTokenJwtPayload = {
oidc?: { oidc?: {
claims: Record<string, string>; claims: Record<string, string>;
}; };
kubernetes?: {
namespace: string;
name: string;
};
}; };
}; };
@@ -416,7 +416,13 @@ export const identityKubernetesAuthServiceFactory = ({
{ {
identityId: identityKubernetesAuth.identityId, identityId: identityKubernetesAuth.identityId,
identityAccessTokenId: identityAccessToken.id, identityAccessTokenId: identityAccessToken.id,
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN,
identityAuth: {
kubernetes: {
namespace: targetNamespace,
name: targetName
}
}
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
// akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
@@ -61,6 +61,18 @@ For methods like OIDC, these come as claims in the token and can be made availab
``` ```
<img src="/images/platform/access-controls/abac-policy-oidc-format.png" /> <img src="/images/platform/access-controls/abac-policy-oidc-format.png" />
</Tab>
<Tab title="Kubernetes Login Attributes">
For identities authenticated using Kubernetes, the service account's namespace and name are available in their policy and can be accessed as follows:
```
{{ identity.auth.kubernetes.namespace }}
{{ identity.auth.kubernetes.name }}
```
<img src="/images/platform/access-controls/abac-policy-k8s-format.png" />
</Tab> </Tab>
<Tab title="Other Authentication Method Attributes"> <Tab title="Other Authentication Method Attributes">
At the moment we only support OIDC claims. Payloads on other authentication methods are not yet accessible. At the moment we only support OIDC claims. Payloads on other authentication methods are not yet accessible.
Binary file not shown.

After

Width:  |  Height:  |  Size: 538 KiB