pub enum InternalAuthConfig {
SharedSecret {
secret: SecretString,
peer_name: String,
},
Kube {
audiences: Vec<String>,
token_path: Option<PathBuf>,
},
}Expand description
Platform-plane authentication provider selection.
Serialized with an internal provider tag, e.g.
internal_auth:
provider: shared_secret
secret: "dev-internal-token"
peer_name: "hello"or
internal_auth:
provider: kube
audiences: ["toolkit-internal"]
token_path: /var/run/secrets/tokens/toolkit-internalVariants§
A single pre-shared secret (dev / single-node). See the module docs.
Kube
A projected Kubernetes ServiceAccount token (Profile 3).
Fields
audiences: Vec<String>Expected token audiences for TokenReview (inbound).
Required, and must not be empty. An empty list disables audience
binding twice over in toolkit-k8s-auth: no audience is sent to the
API server, and the client-side comparison against the response is
skipped. Any ServiceAccount token the API server accepts — from
any workload in the cluster, issued for any audience — would then
authenticate as a platform peer.
It used to default to empty, so a config that simply omitted the field got that silently.
Implementations§
Source§impl InternalAuthConfig
impl InternalAuthConfig
Sourcepub fn build_authenticator(
&self,
) -> Result<BuiltAuthenticator, InvalidInternalAuth>
pub fn build_authenticator( &self, ) -> Result<BuiltAuthenticator, InvalidInternalAuth>
Build the inbound validator when it can be constructed without a heavier backend.
§Errors
Returns InvalidInternalAuth::SharedSecret when the configured shared
secret is unusable — empty, or the redaction placeholder from a
serialized config. Returns InvalidInternalAuth::EmptyKubeAudiences
when provider: kube has no configured audiences.
The static outbound credential for the shared-secret provider, if any.
Sourcepub fn kube_audiences(&self) -> Option<&[String]>
pub fn kube_audiences(&self) -> Option<&[String]>
The configured TokenReview audiences for the Kubernetes provider.
Sourcepub fn kube_token_path(&self) -> Option<&Path>
pub fn kube_token_path(&self) -> Option<&Path>
The projected-token path for the Kubernetes provider’s outbound credential, if configured.
Trait Implementations§
Source§impl Clone for InternalAuthConfig
impl Clone for InternalAuthConfig
Source§fn clone(&self) -> InternalAuthConfig
fn clone(&self) -> InternalAuthConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for InternalAuthConfig
Manual Debug that never renders the shared secret. The derived impl would
print secret verbatim, leaking the platform-plane credential into any
{:?} sink (config tracing, panic messages, error context). All other
fields — including peer_name and the Kube variant — are shown as-is.
impl Debug for InternalAuthConfig
Manual Debug that never renders the shared secret. The derived impl would
print secret verbatim, leaking the platform-plane credential into any
{:?} sink (config tracing, panic messages, error context). All other
fields — including peer_name and the Kube variant — are shown as-is.
Source§impl<'de> Deserialize<'de> for InternalAuthConfig
impl<'de> Deserialize<'de> for InternalAuthConfig
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Source§impl Serialize for InternalAuthConfig
Manual Serialize that never emits the shared secret in plaintext.
impl Serialize for InternalAuthConfig
Manual Serialize that never emits the shared secret in plaintext.
A derived Serialize would write secret verbatim, leaking the
platform-plane credential whenever a containing config is serialized — most
notably AppConfig::to_yaml behind --print-config. Instead the secret is
replaced with a <redacted> placeholder; every other field (and the
internally-tagged provider shape) is preserved so the output still round-
trips structurally.
This is safe because the config is only ever deserialized to obtain the real secret; serialization is used for diagnostics, never to transmit the credential.