Repository navigation
Fetch organization repositories with Workload Identity - #238
Merged
Merged
Conversation
A repository request to a Hex.pm organization that resolves no other
credentials now exchanges the CI job's OIDC token for a token scoped to
the organization's repository (repository:ORG), which hexpm issues to an
organization workload identity with the read or write role.
Build tools opt in by providing the new get_workload_identity_token and
persist_workload_identity_token callbacks, which keep the outcome of the
last exchange for each repository. Without somewhere to keep it every
request would exchange a new OIDC token, so a build tool without them
resolves repository credentials as before.
A kept token is reused until it's within five minutes of expiring, and
the exchange holds the repo lock so concurrent requests share one. A
token_expired 401 exchanges again, unless another request already
replaced the rejected token.
A failed exchange is kept too, so it isn't repeated for every request:
hexpm counts each failed exchange against a limit per GitHub repository.
The workload identity was only picked up from the CI job, so with
optional set the request then runs without credentials, as it would
outside CI, and a mirror that authenticates another way still works. A
401 or 403 to that request, or a failed renewal, returns
{error, {auth_error, {workload_identity_failed, Reason}}}.
The jwt-bearer exchange now requires expires_in in the token response,
which hexpm always sends.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A repository request to a Hex.pm organization that resolves no other credentials now exchanges the CI job's OIDC token for a
repository:ORGtoken. hexpm issues those to organization workload identities with thereadorwriterole since hexpm/hexpm@a746876. Organization keys,HEX_REPOS_KEYand a user session still come first.Build tools opt in with two new optional callbacks,
get_workload_identity_tokenandpersist_workload_identity_token, which keep the outcome of the last exchange for each repository in memory. Without them every request would exchange a new OIDC token, so a build tool that doesn't provide them resolves repository credentials as before.token_expired401 exchanges again unless another request already replaced the rejected token.{error, {auth_error, {workload_identity_failed, Reason}}}.expires_inin the token response, which hexpm always sends. This applies toworkload_identity_auth/2too.