fix(ateclient): auto-refresh the ateapi bearer token - #694
Open
Kyosuke Konishi (konippi) wants to merge 1 commit into
Open
fix(ateclient): auto-refresh the ateapi bearer token#694Kyosuke Konishi (konippi) wants to merge 1 commit into
Kyosuke Konishi (konippi) wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #644
internal/ateclientminted a single 1-hour ServiceAccount token at dial time and never re-minted it, so any client outliving the token failed every RPC withUnauthenticated: invalid bearer token: jwt has expireduntil a full reconnect.This replaces the static string credential with a refreshing
credentials.PerRPCCredentialsbacked by the TokenRequest API: the cached token is served while a background refresh starts at 80% of the remaining lifetime (kubelet's threshold, with a per-token 0-10s jitter), tokens stop being used 30s before issuer expiry to cover RPC transit and clock skew, concurrent callers share a single in-flight refresh that is detached from the initiating caller's cancellation and bounded by a 10s timeout, and refresh failures fall back to the still-usable old token with 1s..30s jittered exponential backoff — an expired token is never sent (fail closed). Token values never appear in errors or logs, andRequireTransportSecuritystays true.