feat(auth): trust the k8s cluster OIDC issuer for ServiceAccount tokens (ADR-0011 D1)
CD / Lint / Test / Vet (push) Successful in 17s
CD / Build & Import (push) Successful in 22s
CD / Deploy via GitOps (push) Successful in 3s

Additive: gitea-mcp now validates JWTs from a LIST of issuers — the existing
Authentik issuer (DEX_ISSUER_URL) AND, when K8S_ISSUER_URL is set, the in-cluster
k8s OIDC issuer for audience-bound ServiceAccount tokens. Lets in-cluster pods
authenticate with kubelet-rotated projected SA tokens instead of a static bearer.

- config: K8S_ISSUER_URL + K8S_MCP_AUDIENCE.
- cmd/gitea-mcp/k8soidc.go: HTTP client that fetches the k8s OIDC discovery/JWKS
  with the cluster CA + this pod's SA bearer (k3s requires an authed fetch;
  anonymous is 401).
- main.go: build the issuer list; switch NewJWTValidator -> NewMultiJWTValidator.
  The k8s issuer is best-effort — if its client can't be built (not in a pod) or
  its discovery is unreachable at startup, it is DROPPED and we fall back so
  Authentik/static auth is never taken down. Smoke-tested: off-pod it logs the
  skip and starts static-only; static-bearer /mcp returns 400 (auth passed), not 401.
- bump mcp-chassis v0.3.0 -> v0.5.0 (multi-issuer + per-issuer HTTPClient).

Refs infra ADR-0011; enables retiring the in-cluster static bearer.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-07 00:16:39 +02:00
co-authored by Claude Opus 4.8
parent 51b823ae79
commit 240c3ec081
5 changed files with 92 additions and 4 deletions
+4
View File
@@ -15,6 +15,8 @@ type Config struct {
DexIssuerURL string // DEX_ISSUER_URL, e.g. https://auth.d-ma.be; empty disables JWT auth
MCPAudience string // MCP_AUDIENCE, JWT audience claim to validate, e.g. claude-ai
MCPResourceURL string // MCP_RESOURCE_URL, this server's public URL for /.well-known metadata
K8sIssuerURL string // K8S_ISSUER_URL, in-cluster OIDC issuer for ServiceAccount-token auth (ADR-0011 D1); empty disables
K8sAudience string // K8S_MCP_AUDIENCE, required audience claim for k8s SA tokens
}
func Load() (Config, error) {
@@ -28,6 +30,8 @@ func Load() (Config, error) {
DexIssuerURL: os.Getenv("DEX_ISSUER_URL"),
MCPAudience: os.Getenv("MCP_AUDIENCE"),
MCPResourceURL: os.Getenv("MCP_RESOURCE_URL"),
K8sIssuerURL: os.Getenv("K8S_ISSUER_URL"),
K8sAudience: os.Getenv("K8S_MCP_AUDIENCE"),
}
return cfg, nil
}