Repository navigation
Conversation
The new feature gate will initially be enabled for TechPreviewNoUpgrade. This feature extends ExternalOIDC with a webhook that enables sourcing claims from external sources.
Rewrite ConfigOAuthEnabled as an explicit switch on known authentication types instead of a negation check against OIDC. Inline the private oauthEnabled helper into HCPOAuthEnabled and remove unused HCOAuthEnabled.
…ourcing is enabled When the ExternalOIDCExternalClaimsSourcing feature gate is enabled, configure KAS to always use the webhook token authenticator regardless of authentication type; with that feature, even external OIDC will go via the webhook instead of --authentication-config.
…dapt functions The oauth-apiserver deployment manifest is slimmed to base-only fields shared by both modes. Each mode gets its own adapt function and file: adaptForOAuth (IntegratedOAuth) and adaptForExternalOIDC (external-oidc). The component predicate is updated to keep the component alive when ExternalOIDCExternalClaimsSourcing is enabled.
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
|
Skipping CI for Draft Pull Request. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: liouk The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #8920 +/- ##
==========================================
+ Coverage 40.69% 41.73% +1.04%
==========================================
Files 755 518 -237
Lines 93373 80905 -12468
==========================================
- Hits 37994 33763 -4231
+ Misses 52646 44796 -7850
+ Partials 2733 2346 -387
... and 355 files with indirect coverage changes
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
|
I now have all evidence from all four jobs. Let me compile the final report. Test Failure Analysis CompleteJob Information
Test Failure AnalysisErrorSummaryAll four failures stem from a single root cause: the PR refactors the Root CauseThe PR introduces the
The deployment.yaml asset was stripped to a bare minimum (only the serving-cert volume mount remains in the template), and each path programmatically adds its required args, volume mounts, volumes, probes, and sidecar containers. This architectural change causes the Specific failures:
Recommendations
Evidence
|
|
PR needs rebase. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Closing this POC -- we'll use #8921 instead. /close |
|
@liouk: Closed this PR. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
This PR is for demonstration purposes only and should not be merged as-is.
/hold
Explores keeping a single oauth-apiserver component and forking its deployment adapt logic based on auth mode. When the
ExternalOIDCExternalClaimsSourcinggate is enabled and auth type is OIDC, the existing oauth-apiserver component stays alive but uses a separate adapt function (adaptDeploymentOIDC) that rewrites the container to run theexternal-oidcsubcommand with a different config. Shares the predicate, manifests, and component registration — only the deployment shape diverges.