Aram Price and Ryan Richard
1b5e8c3439
Upstream Watcher Controller Syncs less often by adjusting its filters
...
- Only watches Secrets of type "secrets.pinniped.dev/oidc-client"
Signed-off-by: Ryan Richard <richardry@vmware.com >
2020-12-18 15:41:18 -08:00
aram price and Ryan Richard
cc5af1a810
Fix lint error
...
Signed-off-by: Ryan Richard <richardry@vmware.com >
2020-12-18 15:28:56 -08:00
aram price
cff2dc1379
Reorder functions
2020-12-18 15:08:55 -08:00
Aram Price and Ryan Richard
b3e428c9de
Several more controllers Sync less often by adjusting their filters
...
- JWKSWriterController
- JWKSObserverController
- FederationDomainSecretsController for HMAC keys
- FederationDomainSecretsController for state signature key
- FederationDomainSecretsController for state encryption key
Signed-off-by: Ryan Richard <richardry@vmware.com >
2020-12-18 14:55:05 -08:00
aram price and Ryan Richard
187bd9060c
All FederationDomain Secrets have distinct Types
...
Signed-off-by: Ryan Richard <richardry@vmware.com >
2020-12-17 17:07:38 -08:00
aram price
587cced768
Add extra type info where SecretType is used
2020-12-17 15:43:20 -08:00
Aram Price and Ryan Richard
55483b726b
More "op" and "opc" local variable renames
...
Signed-off-by: Ryan Richard <richardry@vmware.com >
2020-12-17 13:49:53 -08:00
Aram Price and Andrew Keesler
a33dace80b
Upgrade golang (1.15.5 -> 1.15.6)
...
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-12-16 13:31:54 -05:00
aram price
78df80f128
Tests ensure OIDCProvider secrets exist
...
... whenever one is successfully created.
2020-12-15 18:26:27 -08:00
Aram Price and Andrew Keesler
0bd428e45d
test/integration: more logging to track down flakes
...
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-12-15 16:52:57 -05:00
aram price and Andrew Keesler
2edcdc92f4
Log when unexpected Upstream OIDC Providers found
...
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-12-15 10:49:13 -08:00
aram price
e03e344dcd
SecretHelper depends less on OIDCProvider
...
This should allow the helper to be more generic so that it can be used
with the SupervisorSecretsController
2020-12-14 19:35:45 -08:00
aram price
bf86bc3383
Rename for clarity
2020-12-14 18:36:56 -08:00
aram price
b799515f84
Pull symmetricsecrethelper package up to generator
...
- rename symmetricsecrethelper.New => generator.NewSymmetricSecretHelper
2020-12-14 17:41:02 -08:00
aram price
b1ee434ddf
Rename in preparation for refactor
2020-12-14 16:44:27 -08:00
aram price
6e8d564013
Test filters in SupervisorSecretsController
2020-12-14 16:08:48 -08:00
Aram Price and Andrew Keesler
5b7a86ecc1
Integration test for Supervisor secret controllers
...
This forced us to add labels to the CSRF cookie secret, just as we do
for other Supervisor secrets. Yay tests.
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-12-14 15:53:12 -05:00
aram price and Andrew Keesler
3ca877f1df
WIP - preliminary OIDCProviderSecrets controller
...
Tests not yet passing, controller is incomplete and expectations may be
incorrect.
2020-12-13 17:37:49 -05:00
aram price and Andrew Keesler
3e31668eb0
Refactor some utilitiy methods for sharing.
2020-12-13 17:37:48 -05:00
aram price and Andrew Keesler
9e2213cbae
Rename for clarity
...
- makes space for OIDCPrivder related controller
2020-12-13 17:37:48 -05:00
aram price
a3285fc187
Fix variable / package name collision
2020-12-10 17:32:55 -08:00
aram price
e1173eb5eb
manager.Manager is initialized with secret.Cache
...
- hard-coded secret.Cache is passed in from pinniped-supervisor/main
2020-12-10 17:32:55 -08:00
aram price
72bc458c8e
Manager uses secret.Cach with hardcoded values
2020-12-10 17:32:55 -08:00
aram price
2f87be3f94
Manager uses dynamiccodec.Codec for cookie encoding
...
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-12-10 17:32:55 -08:00
aram price
ccac124b7a
Fix broken test
...
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-12-10 17:32:55 -08:00
aram price
030edaf72d
KeyFunc no longer uses multi-value return
...
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-12-10 17:32:55 -08:00
aram price
86c75b7a80
CSRF cookie is no longer encrypted
2020-12-09 17:34:02 -08:00
aram price
f1f8ffa456
Distinct Encoder's use distinct keys
2020-12-09 17:34:02 -08:00
aram price
4a5f8e30a8
Use distinct Encoder for state and csrf data
2020-12-09 17:34:02 -08:00
aram price
e111ca02da
Use the narrowest possible interface
2020-12-09 17:34:02 -08:00
aram price
6ec3589112
Use recorder Cookies() helper
...
- replaces hand-parsing of cookie strings
2020-12-09 17:34:02 -08:00
Aram Price and Andrew Keesler
9ed5dcb031
Only create underlying jwt authenticator when spec has changed
...
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-12-08 15:41:49 -05:00
aram price
8d2b8ae6b5
Use constants for scope values
2020-12-08 10:46:05 -08:00
Aram Price and Ryan Richard
d91baba240
authorize and callback endpoints now handle the offline_access scope
...
- This is in preparation for the token endpoint to support the refresh
grant
Signed-off-by: Ryan Richard <richardry@vmware.com >
2020-12-07 17:22:34 -08:00
Aram Price and Ryan Richard
648fa4b9ba
Backfill test for token endpoint error when JWK is not yet available
...
Signed-off-by: Ryan Richard <richardry@vmware.com >
2020-12-07 11:53:24 -08:00
Aram Price and Ryan Richard
ac19782405
Merge branch 'main' into token-endpoint
...
Signed-off-by: Ryan Richard <richardry@vmware.com >
2020-12-04 15:52:49 -08:00
Aram Price and Ryan Richard
26a8747509
Use the more specific label name of "storage.pinniped.dev/type"
...
Instead of the less specific "storage.pinniped.dev"
Signed-off-by: Ryan Richard <richardry@vmware.com >
2020-12-04 14:39:11 -08:00
aram price
05085d8e23
Use anonymous interface in test for Storage
2020-12-03 11:26:36 -08:00
aram price and Andrew Keesler
7fa8f7797a
hack/module.sh learns codegen_verify
2020-08-18 09:50:07 -04:00
aram price and Andrew Keesler
a456daa0b2
./hack/module.sh learns codegen command
...
Runs code generation on a per-module basis. If `CONTAINED` is not set
the code generation is run in a container.
Mount point in docker is randomzied to simulate Concourse.
Introduce K8S_PKG_VERSION to make room to build different versions
eventually.
2020-08-18 09:50:07 -04:00
aram price
87b9ff2131
Set MOD_DIR correctly
2020-08-14 15:58:50 -07:00
aram price
a45748f020
hack/module.sh sets MOD_DIR for module tasks
...
This is to allow tasks which need to be executed in a module-specific
context to detect that they are being invoked appropriately.
2020-08-14 15:08:24 -07:00
aram price
e48d9faf27
Normalize ROOT naming and calculation in hack/
2020-08-12 08:34:17 -07:00
Aram Price and Andrew Keesler
0806074d94
hack/update-codegen.sh: really fix symlink paths
...
This is totally gonna be it.
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-08-11 14:50:43 -04:00
Aram Price and Andrew Keesler
13d4a38eca
hack/update-codegen.sh: fix symlink paths
...
Wow fun times with symlinks. We *think* this script should work in CI
now...but we'll see.
Previously we were seeing a false positive where even though the generated
code was out of date, the CI step did not report failure.
Signed-off-by: Andrew Keesler <akeesler@vmware.com >
2020-08-11 14:41:04 -04:00
aram price and Matt Moyer
9e9868bd16
Add hack/module.sh script to run module tasks
...
The script knows `tidy`, `lint`, and `test`
2020-08-06 20:09:15 -05:00
aram price
bd594e19ff
Update -api and -client-go dependencies
...
- pulls in chage to make ExpirationTimestamp mandatory on
LoginRequestCredential
2020-07-30 20:05:32 -07:00