This is an automated email from the ASF dual-hosted git repository. lahirujayathilake pushed a commit to branch auth-endpoints in repository https://gitbox.apache.org/repos/asf/airavata-custos.git
commit e1d03667f2467ef8911599f3edac8e90032a2868 Author: lahiruj <[email protected]> AuthorDate: Tue Jun 16 19:11:01 2026 -0400 Add auth config block for issuer, audience, JWKS URL Co-Authored-By: Claude Opus 4.7 <[email protected]> --- config/custos.yaml | 3 +++ config/{custos.yaml => custos.yaml.example} | 16 +++++++++++++--- internal/config/config.go | 10 ++++++++++ 3 files changed, 26 insertions(+), 3 deletions(-) diff --git a/config/custos.yaml b/config/custos.yaml index ca8e749f1..d8f910886 100644 --- a/config/custos.yaml +++ b/config/custos.yaml @@ -3,6 +3,9 @@ core: url: "${DATABASE_DSN}" api: port: 8080 + auth: + issuer: "${OIDC_ISSUER_URL}" + audience: "${OIDC_AUDIENCE}" log_level: "info" connectors: diff --git a/config/custos.yaml b/config/custos.yaml.example similarity index 67% copy from config/custos.yaml copy to config/custos.yaml.example index ca8e749f1..782532948 100644 --- a/config/custos.yaml +++ b/config/custos.yaml.example @@ -1,8 +1,18 @@ +# Custos configuration template. Copy to config/custos.yaml and either +# replace the ${ENV_VAR} placeholders with literal values or export them +# in the runtime environment. Anything secret-shaped (DSN passwords, +# API keys, OIDC client secrets) must come from the environment, never +# from a committed YAML. + core: database: - url: "${DATABASE_DSN}" + url: "${DATABASE_DSN}" # MariaDB DSN api: port: 8080 + auth: + issuer: "${OIDC_ISSUER_URL}" # OIDC IdP issuer URL + audience: "${OIDC_AUDIENCE}" # JWT audience claim the IdP issues for this server + # jwks_url: "" # optional override; leave empty to discover via issuer log_level: "info" connectors: @@ -13,7 +23,7 @@ connectors: url: "https://slurm-api.example.com" version: "0.0.38" username: "slurm_admin" - token: "${SLURM_TOKEN}" # Reference to environment variable + token: "${SLURM_TOKEN}" slurm-usage-monitor: type: "slurm-usage-monitor" @@ -22,7 +32,7 @@ connectors: url: "https://slurm-api.example.com" version: "0.0.38" username: "slurm_admin" - token: "${SLURM_TOKEN}" # Reference to environment variable + token: "${SLURM_TOKEN}" cluster_id: "slurm-cluster" comanage-provisioner: diff --git a/internal/config/config.go b/internal/config/config.go index bbffcfb92..24de001aa 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -34,6 +34,7 @@ type Config struct { type CoreConfig struct { Database DatabaseConfig `yaml:"database"` API APIConfig `yaml:"api"` + Auth AuthConfig `yaml:"auth"` LogLevel string `yaml:"log_level"` } @@ -45,6 +46,15 @@ type APIConfig struct { Port int `yaml:"port"` } +// AuthConfig drives OIDC bearer token verification at the HTTP boundary. +// Issuer + Audience are required at runtime; JWKSURL is an override the +// HTTP-layer integration tests use to point at an in-process JWKS server. +type AuthConfig struct { + Issuer string `yaml:"issuer"` + Audience string `yaml:"audience"` + JWKSURL string `yaml:"jwks_url"` +} + type ConnectorConfig struct { Type string `yaml:"type"` Enabled bool `yaml:"enabled"`
