feat(orbit): add internal cloud connector token endpoint

What does this MR do and why?

Adds a read-only internal API endpoint that lets GitLab Orbit's indexer fetch the instance Cloud Connector token. Orbit needs this credential to authenticate billing-event emission on Self-Managed and Dedicated instances, where the GitLab.com workload-identity token it normally uses is not available. The endpoint returns only the token, is gated behind the existing knowledge_graph_infra flag, and reuses the same JWT authentication as the other internal Orbit endpoints. The token carries its own exp claim, so callers that need the expiry decode it from the token rather than relying on a separate field.

Related to https://gitlab.com/gitlab-org/orbit/knowledge-graph/-/work_items/1229

Screenshots or screen recordings

N/A — backend-only internal API endpoint.

How to set up and validate locally

  1. Enable the feature flag in Rails console:

    Feature.enable(:knowledge_graph_infra)
  2. Create a Cloud Connector token locally (GDK instances do not sync from CustomersDot by default):

    CloudConnector::ServiceAccessToken.create!(
      token: JWT.encode({ exp: 1.hour.from_now.to_i }, nil, 'none'),
      expires_at: 1.hour.from_now
    )
  3. Generate a valid indexer JWT with the Knowledge Graph shared secret:

    secret = Analytics::KnowledgeGraph::JwtAuth.secret
    payload = {
      'sub' => 'gkg-indexer:code',
      'iss' => Analytics::KnowledgeGraph::JwtAuth::ISSUER,
      'aud' => Analytics::KnowledgeGraph::JwtAuth::AUDIENCE,
      'exp' => 10.minutes.from_now.to_i
    }
    token = JWT.encode(payload, secret, 'HS256')
  4. Happy path: Call the endpoint with a valid indexer JWT:

    curl -i -H "Gitlab-Orbit-Api-Request: <token>" http://gdk.test:3000/api/v4/internal/orbit/cloud_connector_token

    Expected response: 200 OK with body {"token":"..."}.

  5. Deny path: Call the endpoint with a JWT whose sub is not prefixed gkg-indexer: (e.g., sub => 'user:1'):

    curl -i -H "Gitlab-Orbit-Api-Request: <token-with-wrong-sub>" http://gdk.test:3000/api/v4/internal/orbit/cloud_connector_token

    Expected response: 401 Unauthorized with body {"message":"Knowledge Graph JWT authentication invalid"}.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Why router-sync is skipped

The routes sync MR merged - gitlab-org/cells/http-router!1351 (merged) but the job is still failing on other routes which are not related to this MR. Hence the pipeline:skip-router-sync label was added to unblock the MR as it is needed for Orbit GA.

Edited by Sharmad Nachnolkar

Merge request reports

Loading
Loading