Skip to content

[awf] api-proxy: no cloud Workload Identity Federation exchange for OTLP export auth #6921

Description

@lpcox

Problem
OTLP export authentication only supports GitHub-issued credentials (static secret header, GitHub App token, GitHub Actions OIDC JWT). There is no way to exchange a GitHub OIDC token for a cloud-issued access token (e.g. Google WIF/STS), so cloud-native OTLP endpoints like telemetry.googleapis.com that require their own tokens cannot be reached without standing up a separate collector.

Context
Original report: github/gh-aw#50013

Root Cause
The per-job OIDC minting path (generateOTLPOIDCMintStep) only produces a raw GitHub OIDC JWT. There is no token-exchange step to swap that JWT for a cloud provider access token via Workload Identity Federation/STS, and no firewall allowlist entries for provider STS endpoints (e.g. sts.googleapis.com).

Proposed Solution
Extend the OTLP OIDC mint path with an optional workload-identity config block (provider, audience, service-account) that performs the STS exchange per span-emitting job (agent, activation, conclusion, safe_outputs) before setting the Authorization header. Automatically grant id-token: write on those jobs and add the provider's token-exchange host(s) to the AWF egress allowlist so the exchange call itself is not blocked.

Generated by Firewall Issue Dispatcher · auto · 32.3 AIC · ⊞ 9K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions