Commit cdcba2f
Feat: Enable
* Introduce authenticator engine and make proxy auth work
Signed-off-by: Fabio Grätz <[email protected]>
* Use proxy authed session for client credentials flow
Signed-off-by: Fabio Grätz <[email protected]>
* Don't use authenticator engine but do proxy authentication via existing external command authenticator
Signed-off-by: Fabio Grätz <[email protected]>
* Add docstring to AuthenticationHTTPAdapter
Signed-off-by: Fabio Grätz <[email protected]>
* Address todo in docstring
Signed-off-by: Fabio Grätz <[email protected]>
* Create blank session if none provided
Signed-off-by: Fabio Grätz <[email protected]>
* Create blank session if none provided in get_token
Signed-off-by: Fabio Grätz <[email protected]>
* Refresh proxy creds in session when not existing without triggering 401
Signed-off-by: Fabio Grätz <[email protected]>
* Add test for get_session
Signed-off-by: Fabio Grätz <[email protected]>
* Move auth helper test into existing module
Signed-off-by: Fabio Grätz <[email protected]>
* Move auth helper test into existing module
Signed-off-by: Fabio Grätz <[email protected]>
* Add test for upgrade_channel_to_proxy_authenticated
Signed-off-by: Fabio Grätz <[email protected]>
* Auth helper tests without use of responses package
Signed-off-by: Fabio Grätz <[email protected]>
* Feat: Add plugin for generating GCP IAP ID tokens via external command (#1795)
* Add external command plugin to generate id tokens for identity aware proxy
Signed-off-by: Fabio Grätz <[email protected]>
* Retrieve desktop app client secret from gcp secret manager
Signed-off-by: Fabio Grätz <[email protected]>
* Remove comments
Signed-off-by: Fabio Grätz <[email protected]>
* Introduce a command group that allows adding a command to generate service account id tokens later
Signed-off-by: Fabio Grätz <[email protected]>
* Document how to use plugin and deploy Flyte with IAP
Signed-off-by: Fabio Grätz <[email protected]>
* Minor corrections README.md
Signed-off-by: Fabio Grätz <[email protected]>
---------
Signed-off-by: Fabio Grätz <[email protected]>
Co-authored-by: Fabio Grätz <[email protected]>
Signed-off-by: Fabio Grätz <[email protected]>
* Use proxy auth'ed session for device code auth flow
Signed-off-by: Fabio Grätz <[email protected]>
* Fix token client tests
Signed-off-by: Fabio Grätz <[email protected]>
* Make poll token endpoint test more specific
Signed-off-by: Fabio Grätz <[email protected]>
* Make test_client_creds_authenticator test work and more specific
Signed-off-by: Fabio Grätz <[email protected]>
* Make test_client_creds_authenticator_with_custom_scopes test work and more specific
Signed-off-by: Fabio Grätz <[email protected]>
* Implement subcommand to generate id tokens for service accounts
Signed-off-by: Fabio Graetz <[email protected]>
* Test id token generation from service accounts
Signed-off-by: Fabio Graetz <[email protected]>
* Fix plugin requirements
Signed-off-by: Fabio Graetz <[email protected]>
* Document usage of generate-service-account-id-token subcommand
Signed-off-by: Fabio Grätz <[email protected]>
* Document alternative ways to obtain service account id tokens
Signed-off-by: Fabio Grätz <[email protected]>
---------
Signed-off-by: Fabio Grätz <[email protected]>
Signed-off-by: Fabio Graetz <[email protected]>
Co-authored-by: Fabio Grätz <[email protected]>flytekit to authenticate with proxy in front of FlyteAdmin (#1787)1 parent cf165f7 commit cdcba2f
File tree
18 files changed
+1155
-65
lines changed- flytekit
- clients
- auth
- grpc_utils
- configuration
- plugins/flytekit-identity-aware-proxy
- flytekitplugins/identity_aware_proxy
- tests
- tests/flytekit/unit/clients
- auth
18 files changed
+1155
-65
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
184 | 184 | | |
185 | 185 | | |
186 | 186 | | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
187 | 192 | | |
188 | 193 | | |
189 | 194 | | |
| |||
192 | 197 | | |
193 | 198 | | |
194 | 199 | | |
195 | | - | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
196 | 203 | | |
197 | 204 | | |
198 | 205 | | |
| |||
201 | 208 | | |
202 | 209 | | |
203 | 210 | | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
204 | 220 | | |
205 | 221 | | |
206 | 222 | | |
| |||
213 | 229 | | |
214 | 230 | | |
215 | 231 | | |
216 | | - | |
217 | | - | |
218 | | - | |
219 | 232 | | |
220 | 233 | | |
221 | 234 | | |
222 | 235 | | |
| 236 | + | |
223 | 237 | | |
224 | | - | |
| 238 | + | |
225 | 239 | | |
226 | 240 | | |
227 | 241 | | |
| |||
230 | 244 | | |
231 | 245 | | |
232 | 246 | | |
233 | | - | |
234 | | - | |
235 | 247 | | |
236 | 248 | | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
237 | 259 | | |
238 | 260 | | |
239 | 261 | | |
| |||
249 | 271 | | |
250 | 272 | | |
251 | 273 | | |
252 | | - | |
| 274 | + | |
253 | 275 | | |
254 | 276 | | |
255 | 277 | | |
| |||
262 | 284 | | |
263 | 285 | | |
264 | 286 | | |
| 287 | + | |
| 288 | + | |
265 | 289 | | |
266 | 290 | | |
267 | 291 | | |
| 292 | + | |
268 | 293 | | |
269 | 294 | | |
270 | 295 | | |
271 | 296 | | |
272 | 297 | | |
273 | 298 | | |
274 | 299 | | |
| 300 | + | |
| 301 | + | |
275 | 302 | | |
276 | | - | |
| 303 | + | |
277 | 304 | | |
278 | 305 | | |
279 | 306 | | |
280 | 307 | | |
281 | | - | |
282 | | - | |
283 | | - | |
284 | | - | |
285 | | - | |
286 | | - | |
287 | | - | |
288 | 308 | | |
289 | | - | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
290 | 317 | | |
291 | | - | |
| 318 | + | |
292 | 319 | | |
293 | 320 | | |
294 | 321 | | |
| |||
332 | 359 | | |
333 | 360 | | |
334 | 361 | | |
335 | | - | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
336 | 371 | | |
337 | | - | |
338 | | - | |
339 | | - | |
340 | | - | |
341 | | - | |
| 372 | + | |
342 | 373 | | |
343 | 374 | | |
344 | 375 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
| |||
95 | 96 | | |
96 | 97 | | |
97 | 98 | | |
| 99 | + | |
98 | 100 | | |
99 | 101 | | |
100 | 102 | | |
101 | 103 | | |
102 | 104 | | |
103 | 105 | | |
104 | 106 | | |
| 107 | + | |
105 | 108 | | |
106 | 109 | | |
107 | 110 | | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
108 | 117 | | |
109 | 118 | | |
110 | 119 | | |
| |||
115 | 124 | | |
116 | 125 | | |
117 | 126 | | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
118 | 137 | | |
119 | 138 | | |
120 | 139 | | |
| |||
176 | 195 | | |
177 | 196 | | |
178 | 197 | | |
| 198 | + | |
179 | 199 | | |
180 | 200 | | |
181 | 201 | | |
| |||
186 | 206 | | |
187 | 207 | | |
188 | 208 | | |
| 209 | + | |
189 | 210 | | |
190 | 211 | | |
191 | 212 | | |
| |||
211 | 232 | | |
212 | 233 | | |
213 | 234 | | |
| 235 | + | |
214 | 236 | | |
215 | 237 | | |
216 | 238 | | |
| |||
234 | 256 | | |
235 | 257 | | |
236 | 258 | | |
| 259 | + | |
237 | 260 | | |
238 | 261 | | |
239 | 262 | | |
| |||
245 | 268 | | |
246 | 269 | | |
247 | 270 | | |
| 271 | + | |
248 | 272 | | |
249 | 273 | | |
250 | 274 | | |
| |||
255 | 279 | | |
256 | 280 | | |
257 | 281 | | |
258 | | - | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
259 | 289 | | |
260 | 290 | | |
261 | 291 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
| 6 | + | |
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| 19 | + | |
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
| |||
25 | 26 | | |
26 | 27 | | |
27 | 28 | | |
| 29 | + | |
28 | 30 | | |
29 | 31 | | |
30 | 32 | | |
31 | 33 | | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
37 | 40 | | |
38 | 41 | | |
39 | 42 | | |
40 | 43 | | |
41 | 44 | | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
42 | 51 | | |
43 | 52 | | |
44 | 53 | | |
| |||
48 | 57 | | |
49 | 58 | | |
50 | 59 | | |
| 60 | + | |
51 | 61 | | |
52 | 62 | | |
53 | 63 | | |
54 | 64 | | |
55 | | - | |
| 65 | + | |
56 | 66 | | |
57 | | - | |
| 67 | + | |
58 | 68 | | |
59 | 69 | | |
60 | 70 | | |
61 | 71 | | |
62 | 72 | | |
63 | 73 | | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
64 | 78 | | |
65 | 79 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
78 | 78 | | |
79 | 79 | | |
80 | 80 | | |
| 81 | + | |
81 | 82 | | |
82 | 83 | | |
83 | 84 | | |
| |||
103 | 104 | | |
104 | 105 | | |
105 | 106 | | |
106 | | - | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
107 | 111 | | |
108 | 112 | | |
109 | 113 | | |
| |||
125 | 129 | | |
126 | 130 | | |
127 | 131 | | |
| 132 | + | |
128 | 133 | | |
129 | 134 | | |
130 | 135 | | |
| |||
133 | 138 | | |
134 | 139 | | |
135 | 140 | | |
136 | | - | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
137 | 144 | | |
138 | 145 | | |
139 | 146 | | |
| |||
0 commit comments