-
Notifications
You must be signed in to change notification settings - Fork 424
oidc: add option to override discovered issuer URL #315
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
liafizan
reviewed
Sep 16, 2021
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We tried the fix in our environment where our OIDC connect provider has the issuer mismatch problem and this fix worked perfectly! Thank you for working on this
|
Glad this works for you! I think that's the feedback I need. Going to go ahead and merge. |
Closed
5 tasks
ddl-ebrown
added a commit
to dominodatalab/flyte
that referenced
this pull request
Aug 31, 2024
- There are a number of cases where the OIDC discovery url returns one issuer, but its desirable to use a separately configured / named issuer for validation instead. There are cases in Azure where this is necessary due to their non-standard OIDC configuration -- which is why this was originally added: coreos/go-oidc#315 There are also cases where it's necessary to use an in-cluster service address, but browser clients are using the external ingress address. Due to cluster DNS configuration, it's possible that flyteadmin may be unable to resolve or use the public ingress address for an Idp, but the internal service address is available. This configuration change allows for that.
3 tasks
ddl-ebrown
added a commit
to dominodatalab/flyte
that referenced
this pull request
Aug 31, 2024
- There are a number of cases where the OIDC discovery url returns one issuer, but its desirable to use a separately configured / named issuer for validation instead. There are cases in Azure where this is necessary due to their non-standard OIDC configuration -- which is why this was originally added: coreos/go-oidc#315 There are also cases where it's necessary to use an in-cluster service address, but browser clients are using the external ingress address. Due to cluster DNS configuration, it's possible that flyteadmin may be unable to resolve or use the public ingress address for an Idp, but the internal service address is available. This configuration change allows for that. Signed-off-by: ddl-ebrown <ethan.brown@dominodatalab.com>
Sovietaced
pushed a commit
to Sovietaced/flyte
that referenced
this pull request
Apr 17, 2025
- There are a number of cases where the OIDC discovery url returns one issuer, but its desirable to use a separately configured / named issuer for validation instead. There are cases in Azure where this is necessary due to their non-standard OIDC configuration -- which is why this was originally added: coreos/go-oidc#315 There are also cases where it's necessary to use an in-cluster service address, but browser clients are using the external ingress address. Due to cluster DNS configuration, it's possible that flyteadmin may be unable to resolve or use the public ingress address for an Idp, but the internal service address is available. This configuration change allows for that. Signed-off-by: ddl-ebrown <ethan.brown@dominodatalab.com>
ddl-ebrown
added a commit
to dominodatalab/flyte
that referenced
this pull request
Apr 17, 2025
- There are a number of cases where the OIDC discovery url returns one issuer, but its desirable to use a separately configured / named issuer for validation instead. There are cases in Azure where this is necessary due to their non-standard OIDC configuration -- which is why this was originally added: coreos/go-oidc#315 There are also cases where it's necessary to use an in-cluster service address, but browser clients are using the external ingress address. Due to cluster DNS configuration, it's possible that flyteadmin may be unable to resolve or use the public ingress address for an Idp, but the internal service address is available. This configuration change allows for that. Signed-off-by: ddl-ebrown <ethan.brown@dominodatalab.com>
ddl-ebrown
added a commit
to dominodatalab/flyte
that referenced
this pull request
Apr 17, 2025
- There are a number of cases where the OIDC discovery url returns one issuer, but its desirable to use a separately configured / named issuer for validation instead. There are cases in Azure where this is necessary due to their non-standard OIDC configuration -- which is why this was originally added: coreos/go-oidc#315 There are also cases where it's necessary to use an in-cluster service address, but browser clients are using the external ingress address. Due to cluster DNS configuration, it's possible that flyteadmin may be unable to resolve or use the public ingress address for an Idp, but the internal service address is available. This configuration change allows for that. - Regenerated flyteadmin code through mise with: mise x go@1.22 -- make generate Signed-off-by: ddl-ebrown <ethan.brown@dominodatalab.com>
Sovietaced
pushed a commit
to flyteorg/flyte
that referenced
this pull request
Apr 17, 2025
- There are a number of cases where the OIDC discovery url returns one issuer, but its desirable to use a separately configured / named issuer for validation instead. There are cases in Azure where this is necessary due to their non-standard OIDC configuration -- which is why this was originally added: coreos/go-oidc#315 There are also cases where it's necessary to use an in-cluster service address, but browser clients are using the external ingress address. Due to cluster DNS configuration, it's possible that flyteadmin may be unable to resolve or use the public ingress address for an Idp, but the internal service address is available. This configuration change allows for that. - Regenerated flyteadmin code through mise with: mise x go@1.22 -- make generate Signed-off-by: ddl-ebrown <ethan.brown@dominodatalab.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fixes #250
Fixes #212