This is an automated email from the ASF dual-hosted git repository.

lahirujayathilake pushed a commit to branch auth-endpoints
in repository https://gitbox.apache.org/repos/asf/airavata-custos.git

commit a84d5548831cca5ead9b40d42faabb96bb54f575
Author: lahiruj <[email protected]>
AuthorDate: Tue Jun 16 19:11:01 2026 -0400

    Add auth config block for issuer, audience, JWKS URL
---
 config/custos.yaml                          |  3 +++
 config/{custos.yaml => custos.yaml.example} | 16 +++++++++++++---
 internal/config/config.go                   | 10 ++++++++++
 3 files changed, 26 insertions(+), 3 deletions(-)

diff --git a/config/custos.yaml b/config/custos.yaml
index ca8e749f1..d8f910886 100644
--- a/config/custos.yaml
+++ b/config/custos.yaml
@@ -3,6 +3,9 @@ core:
     url: "${DATABASE_DSN}"
   api:
     port: 8080
+  auth:
+    issuer: "${OIDC_ISSUER_URL}"
+    audience: "${OIDC_AUDIENCE}"
   log_level: "info"
 
 connectors:
diff --git a/config/custos.yaml b/config/custos.yaml.example
similarity index 67%
copy from config/custos.yaml
copy to config/custos.yaml.example
index ca8e749f1..782532948 100644
--- a/config/custos.yaml
+++ b/config/custos.yaml.example
@@ -1,8 +1,18 @@
+# Custos configuration template. Copy to config/custos.yaml and either
+# replace the ${ENV_VAR} placeholders with literal values or export them
+# in the runtime environment. Anything secret-shaped (DSN passwords,
+# API keys, OIDC client secrets) must come from the environment, never
+# from a committed YAML.
+
 core:
   database:
-    url: "${DATABASE_DSN}"
+    url: "${DATABASE_DSN}"          # MariaDB DSN
   api:
     port: 8080
+  auth:
+    issuer: "${OIDC_ISSUER_URL}"    # OIDC IdP issuer URL
+    audience: "${OIDC_AUDIENCE}"    # JWT audience claim the IdP issues for 
this server
+    # jwks_url: ""                  # optional override; leave empty to 
discover via issuer
   log_level: "info"
 
 connectors:
@@ -13,7 +23,7 @@ connectors:
       url: "https://slurm-api.example.com";
       version: "0.0.38"
       username: "slurm_admin"
-      token: "${SLURM_TOKEN}" # Reference to environment variable
+      token: "${SLURM_TOKEN}"
 
   slurm-usage-monitor:
     type: "slurm-usage-monitor"
@@ -22,7 +32,7 @@ connectors:
       url: "https://slurm-api.example.com";
       version: "0.0.38"
       username: "slurm_admin"
-      token: "${SLURM_TOKEN}" # Reference to environment variable
+      token: "${SLURM_TOKEN}"
     cluster_id: "slurm-cluster"
 
   comanage-provisioner:
diff --git a/internal/config/config.go b/internal/config/config.go
index bbffcfb92..24de001aa 100644
--- a/internal/config/config.go
+++ b/internal/config/config.go
@@ -34,6 +34,7 @@ type Config struct {
 type CoreConfig struct {
        Database DatabaseConfig `yaml:"database"`
        API      APIConfig      `yaml:"api"`
+       Auth     AuthConfig     `yaml:"auth"`
        LogLevel string         `yaml:"log_level"`
 }
 
@@ -45,6 +46,15 @@ type APIConfig struct {
        Port int `yaml:"port"`
 }
 
+// AuthConfig drives OIDC bearer token verification at the HTTP boundary.
+// Issuer + Audience are required at runtime; JWKSURL is an override the
+// HTTP-layer integration tests use to point at an in-process JWKS server.
+type AuthConfig struct {
+       Issuer   string `yaml:"issuer"`
+       Audience string `yaml:"audience"`
+       JWKSURL  string `yaml:"jwks_url"`
+}
+
 type ConnectorConfig struct {
        Type    string                 `yaml:"type"`
        Enabled bool                   `yaml:"enabled"`

Reply via email to