feat(orbit): add internal cloud connector token endpoint
What does this MR do and why?
Adds a read-only internal API endpoint that lets GitLab Orbit's indexer fetch the instance Cloud Connector token. Orbit needs this credential to authenticate billing-event emission on Self-Managed and Dedicated instances, where the GitLab.com workload-identity token it normally uses is not available. The endpoint returns only the token, is gated behind the existing knowledge_graph_infra flag, and reuses the same JWT authentication as the other internal Orbit endpoints. The token carries its own exp claim, so callers that need the expiry decode it from the token rather than relying on a separate field.
Related to https://gitlab.com/gitlab-org/orbit/knowledge-graph/-/work_items/1229
Screenshots or screen recordings
N/A — backend-only internal API endpoint.
How to set up and validate locally
-
Enable the feature flag in Rails console:
Feature.enable(:knowledge_graph_infra) -
Create a Cloud Connector token locally (GDK instances do not sync from CustomersDot by default):
CloudConnector::ServiceAccessToken.create!( token: JWT.encode({ exp: 1.hour.from_now.to_i }, nil, 'none'), expires_at: 1.hour.from_now ) -
Generate a valid indexer JWT with the Knowledge Graph shared secret:
secret = Analytics::KnowledgeGraph::JwtAuth.secret payload = { 'sub' => 'gkg-indexer:code', 'iss' => Analytics::KnowledgeGraph::JwtAuth::ISSUER, 'aud' => Analytics::KnowledgeGraph::JwtAuth::AUDIENCE, 'exp' => 10.minutes.from_now.to_i } token = JWT.encode(payload, secret, 'HS256') -
Happy path: Call the endpoint with a valid indexer JWT:
curl -i -H "Gitlab-Orbit-Api-Request: <token>" http://gdk.test:3000/api/v4/internal/orbit/cloud_connector_tokenExpected response:
200 OKwith body{"token":"..."}. -
Deny path: Call the endpoint with a JWT whose
subis not prefixedgkg-indexer:(e.g.,sub => 'user:1'):curl -i -H "Gitlab-Orbit-Api-Request: <token-with-wrong-sub>" http://gdk.test:3000/api/v4/internal/orbit/cloud_connector_tokenExpected response:
401 Unauthorizedwith body{"message":"Knowledge Graph JWT authentication invalid"}.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Why router-sync is skipped
The routes sync MR merged - gitlab-org/cells/http-router!1351 (merged) but the job is still failing on other routes which are not related to this MR. Hence the pipeline:skip-router-sync label was added to unblock the MR as it is needed for Orbit GA.