mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 04:27:29 +00:00
Merge pull request #3752 from akhilmhdh/feat/k8s-metadata-auth
feat: added k8s metadata in template policy
This commit is contained in:
Vendored
+4
@@ -119,6 +119,10 @@ declare module "@fastify/request-context" {
|
|||||||
oidc?: {
|
oidc?: {
|
||||||
claims: Record<string, string>;
|
claims: Record<string, string>;
|
||||||
};
|
};
|
||||||
|
kubernetes?: {
|
||||||
|
namespace: string;
|
||||||
|
name: string;
|
||||||
|
};
|
||||||
};
|
};
|
||||||
identityPermissionMetadata?: Record<string, unknown>; // filled by permission service
|
identityPermissionMetadata?: Record<string, unknown>; // filled by permission service
|
||||||
assumedPrivilegeDetails?: { requesterId: string; actorId: string; actorType: ActorType; projectId: string };
|
assumedPrivilegeDetails?: { requesterId: string; actorId: string; actorType: ActorType; projectId: string };
|
||||||
|
|||||||
@@ -155,6 +155,12 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
|
|||||||
oidc: token?.identityAuth?.oidc
|
oidc: token?.identityAuth?.oidc
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
if (token?.identityAuth?.kubernetes) {
|
||||||
|
requestContext.set("identityAuthInfo", {
|
||||||
|
identityId: identity.identityId,
|
||||||
|
kubernetes: token?.identityAuth?.kubernetes
|
||||||
|
});
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case AuthMode.SERVICE_TOKEN: {
|
case AuthMode.SERVICE_TOKEN: {
|
||||||
|
|||||||
@@ -11,5 +11,9 @@ export type TIdentityAccessTokenJwtPayload = {
|
|||||||
oidc?: {
|
oidc?: {
|
||||||
claims: Record<string, string>;
|
claims: Record<string, string>;
|
||||||
};
|
};
|
||||||
|
kubernetes?: {
|
||||||
|
namespace: string;
|
||||||
|
name: string;
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -416,7 +416,13 @@ export const identityKubernetesAuthServiceFactory = ({
|
|||||||
{
|
{
|
||||||
identityId: identityKubernetesAuth.identityId,
|
identityId: identityKubernetesAuth.identityId,
|
||||||
identityAccessTokenId: identityAccessToken.id,
|
identityAccessTokenId: identityAccessToken.id,
|
||||||
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
|
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN,
|
||||||
|
identityAuth: {
|
||||||
|
kubernetes: {
|
||||||
|
namespace: targetNamespace,
|
||||||
|
name: targetName
|
||||||
|
}
|
||||||
|
}
|
||||||
} as TIdentityAccessTokenJwtPayload,
|
} as TIdentityAccessTokenJwtPayload,
|
||||||
appCfg.AUTH_SECRET,
|
appCfg.AUTH_SECRET,
|
||||||
// akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
|
// akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error
|
||||||
|
|||||||
+12
@@ -61,6 +61,18 @@ For methods like OIDC, these come as claims in the token and can be made availab
|
|||||||
```
|
```
|
||||||
|
|
||||||
<img src="/images/platform/access-controls/abac-policy-oidc-format.png" />
|
<img src="/images/platform/access-controls/abac-policy-oidc-format.png" />
|
||||||
|
|
||||||
|
</Tab>
|
||||||
|
<Tab title="Kubernetes Login Attributes">
|
||||||
|
For identities authenticated using Kubernetes, the service account's namespace and name are available in their policy and can be accessed as follows:
|
||||||
|
|
||||||
|
```
|
||||||
|
{{ identity.auth.kubernetes.namespace }}
|
||||||
|
{{ identity.auth.kubernetes.name }}
|
||||||
|
```
|
||||||
|
|
||||||
|
<img src="/images/platform/access-controls/abac-policy-k8s-format.png" />
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Other Authentication Method Attributes">
|
<Tab title="Other Authentication Method Attributes">
|
||||||
At the moment we only support OIDC claims. Payloads on other authentication methods are not yet accessible.
|
At the moment we only support OIDC claims. Payloads on other authentication methods are not yet accessible.
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 538 KiB |
Reference in New Issue
Block a user