Verify JWT audience in internal Kubernetes Agent API endpoint
GitLab Kubernetes Agent Server sends JWT-signed requests to the internal API exposed by the monolith. As part of token validation, check that the audience of the token is gitlab
. See gitlab-org/cluster-integration/gitlab-agent!114 (merged)
Designs
- Show closed items
Activity
-
Newest first Oldest first
-
Show all activity Show comments only Show history only
- Mikhail Mazurskiy added to epic &3329
added to epic &3329
- 🤖 GitLab Bot 🤖 added typefeature label
added typefeature label
- Mikhail Mazurskiy mentioned in merge request gitlab-org/cluster-integration/gitlab-agent!114 (merged)
mentioned in merge request gitlab-org/cluster-integration/gitlab-agent!114 (merged)
- Maintainer
In the simplest form of rolling this out, kas must be upgraded before gitlab, right?
1 Collapse replies - Author Maintainer
@hfyngvason Excellent observation, yes.
- Author Maintainer
Hm, we already send the
aud
claim, so rollout order doesn't matter.
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#548 (closed)
mentioned in issue gitlab-org/quality/triage-reports#548 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#624 (closed)
mentioned in issue gitlab-org/quality/triage-reports#624 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#689 (closed)
mentioned in issue gitlab-org/quality/triage-reports#689 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#722 (closed)
mentioned in issue gitlab-org/quality/triage-reports#722 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#812 (closed)
mentioned in issue gitlab-org/quality/triage-reports#812 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#867 (closed)
mentioned in issue gitlab-org/quality/triage-reports#867 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#911 (closed)
mentioned in issue gitlab-org/quality/triage-reports#911 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#1044 (closed)
mentioned in issue gitlab-org/quality/triage-reports#1044 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#1095 (closed)
mentioned in issue gitlab-org/quality/triage-reports#1095 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#1205 (closed)
mentioned in issue gitlab-org/quality/triage-reports#1205 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#1252 (closed)
mentioned in issue gitlab-org/quality/triage-reports#1252 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#1334 (closed)
mentioned in issue gitlab-org/quality/triage-reports#1334 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#2400 (closed)
mentioned in issue gitlab-org/quality/triage-reports#2400 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#2466 (closed)
mentioned in issue gitlab-org/quality/triage-reports#2466 (closed)
- 🤖 GitLab Bot 🤖 mentioned in issue gitlab-org/quality/triage-reports#2547 (closed)
mentioned in issue gitlab-org/quality/triage-reports#2547 (closed)
- Viktor Nagy (GitLab) changed milestone to %Backlog
changed milestone to %Backlog
- Viktor Nagy (GitLab) added environmentsbacklog label
added environmentsbacklog label
- 🤖 GitLab Bot 🤖 added [deprecated] Accepting merge requests label
added [deprecated] Accepting merge requests label
- Mikhail Mazurskiy mentioned in issue gitlab-org/cluster-integration/gitlab-agent#144 (closed)
mentioned in issue gitlab-org/cluster-integration/gitlab-agent#144 (closed)
- 🤖 GitLab Bot 🤖 removed typefeature label
removed typefeature label
- 🤖 GitLab Bot 🤖 added groupenvironments label and removed groupconfigure [DEPRECATED] label
added groupenvironments label and removed groupconfigure [DEPRECATED] label
- 🤖 GitLab Bot 🤖 added devopsdeploy label and removed devopsconfigure [DEPRECATED] label
added devopsdeploy label and removed devopsconfigure [DEPRECATED] label
- Mikhail Mazurskiy removed [deprecated] Accepting merge requests label
removed [deprecated] Accepting merge requests label
- Mikhail Mazurskiy added quick win label
added quick win label
- Mikhail Mazurskiy added featureenhancement typefeature labels and removed typemaintenance label
added featureenhancement typefeature labels and removed typemaintenance label
- Mikhail Mazurskiy set weight to 1
set weight to 1
- Mikhail Mazurskiy added ruby workflowready for development labels
added ruby workflowready for development labels
- Mikhail Mazurskiy removed ruby label
removed ruby label
- Viktor Nagy (GitLab) added workflowplanning breakdown label and removed workflowready for development label
added workflowplanning breakdown label and removed workflowready for development label
- 🤖 GitLab Bot 🤖 added sectioncd label and removed sectionops label
added sectioncd label and removed sectionops label
mentioned in issue gitlab-org/ci-cd/deploy-stage/environments-group/general#32 (closed)
- Viktor Nagy (GitLab) added workflowready for development label and removed workflowplanning breakdown label
added workflowready for development label and removed workflowplanning breakdown label
- Nicolò Maria Mezzopera changed milestone to %16.3
changed milestone to %16.3
- Timo Furrer assigned to @timofurrer
assigned to @timofurrer
- Timo Furrer created branch
267958-verify-jwt-audience-in-internal-kubernetes-agent-api-endpoint
to address this issuecreated branch
267958-verify-jwt-audience-in-internal-kubernetes-agent-api-endpoint
to address this issue - Timo Furrer mentioned in merge request !126695 (merged)
mentioned in merge request !126695 (merged)
- Timo Furrer mentioned in commit 5562067b
mentioned in commit 5562067b
- Timo Furrer mentioned in commit e96622e4
mentioned in commit e96622e4
- Timo Furrer mentioned in commit 0bdf44ec
mentioned in commit 0bdf44ec
- Timo Furrer mentioned in commit 66f01716
mentioned in commit 66f01716
- Timo Furrer mentioned in commit 6f42a6c7
mentioned in commit 6f42a6c7
- Timo Furrer mentioned in commit 02ebb4a5
mentioned in commit 02ebb4a5
- Timo Furrer mentioned in commit 621c6cdd
mentioned in commit 621c6cdd
- Timo Furrer added workflowin review label and removed workflowready for development label
added workflowin review label and removed workflowready for development label
- Timo Furrer closed
closed
- Timo Furrer added workflowcomplete label and removed workflowin review label
added workflowcomplete label and removed workflowin review label
- Timo Furrer mentioned in commit 7cb7b02e
mentioned in commit 7cb7b02e
mentioned in issue gitlab-org/ci-cd/deploy-stage/environments-group/general#34 (closed)