Repository navigation
Send the VenafiConnection's NGTS workspace ID on the token request - #847
Merged
Merged
Conversation
wallrj-cyberark
force-pushed
the
ngts-workspace-id
branch
2 times, most recently
from
October 9, 2026 13:49
7101f5f to
074b420
Compare
wallrj-cyberark
marked this pull request as ready for review
October 9, 2026 13:54
- Bump venafi-connection-lib to pick up spec.ngts.workspaceID. The library sends it as the workspace_id query parameter on the NGTS token request. - Regenerate the VenafiConnection CRD in both charts. Without the new field in the CRD, the API server drops spec.ngts.workspaceID. - The library bump also raises k8s.io/* to v0.37.0 and controller-runtime to v0.25.0, which venafi-connection-lib requires. NGTS now only finds an OIDC (workload identity) service account that lives in a workspace when the token request names that workspace, so the agent cannot use such an account through a VenafiConnection without this change. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Richard Wall <richard.wall@cyberark.com>
wallrj-cyberark
force-pushed
the
ngts-workspace-id
branch
from
October 9, 2026 14:36
074b420 to
383b206
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The agent can now use an NGTS Workload Identity Federation (OIDC) service account that belongs to a workspace. Set
spec.ngts.workspaceIDon the VenafiConnection, and the agent sends it on the token request.Why now?
NGTS changed how it finds OIDC service accounts. If the token request has no
workspace_id, NGTS now only looks at tenant-level accounts. So an OIDC account that lives in a workspace fails with400 invalid_client "Not found", and the agent cannot use it through a VenafiConnection.jetstack/venafi-connection-lib#472 added
spec.ngts.workspaceIDand sends it on the token request. This PR picks that up. Until it is released, you can work around the problem by using a tenant-level service account.What changes
spec.ngts.workspaceID.workspace_idreaches the token request.Without
workspaceID, nothing changes: the token request has noworkspace_idparameter.Example
A VenafiConnection for an agent whose WIF service account belongs to workspace
1000:The discovery-agent chart then points at it as usual:
Leave
workspaceIDunset for a tenant-level service account, and for a private key JWT service account.Please check before merging
The library bump raises k8s.io/* to v0.37.0 and controller-runtime to v0.25.0. venafi-connection-lib's main branch requires them, so Go picks them up automatically.
How this was tested
test-ngts). It passed against a QA tenant, which shows that keypair (private key) auth and uploads still work after the dependency bump. It doesn't use a workspace, so it doesn't exercise the new field.make test-unit: 466 tests pass. The new caseTestVenConnClient_PostDataReadingsWithOptions/ngts_with_workspaceIDcreates a VenafiConnection withworkspaceID: "1000". It checks that the NGTS token request carriesworkspace_id=1000. With the old CRD, the test fails because the API server prunes the unknown field.make verifypasses.What this PR deliberately does not do
workspace_idon uploads. NGTS ignores it there: uploads are scoped to the workspace of the service account that authenticated.--workspace-idflag orconfig.workspaceIDvalue for keypair mode. NGTS identifies a private-key service account by its client ID and ignoresworkspace_id, so the option would have no effect.Generated files
make generate. They also pick up other changes made to the library since the previous pin.LICENSESchanges come from the dependency bump.Release note: the agent can use an NGTS Workload Identity Federation service account that belongs to a workspace. Set
spec.ngts.workspaceIDon the VenafiConnection.[with Claude]