Repository navigation
feat(ai-gateway): add x-api-key SecurityPolicy on the shared Gateway - #69
Closed
atharvamhaske wants to merge 1 commit into
Closed
atharvamhaske wants to merge 1 commit into
atharvamhaske wants to merge 1 commit into
Conversation
Render a SecurityPolicy when `aiGateway.auth.enabled` is true and `aiGateway.auth.existingSecretName` names an Opaque Secret. Clients send `x-api-key`. JWT and OIDC stay out of the chart.
Contributor
Author
|
@spron-in what you think on this ? |
Contributor
|
superseded by #71 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does
The chart can attach one Envoy
SecurityPolicyto the shared AI Gateway.Clients send
x-api-key. A missing or unknown key returns HTTP 401.You create the Secret first. Helm does not generate keys.
The template is
charts/provider-kserve/templates/ai-gateway-auth.yaml.The rendered name is
*-apikey. It only doesapiKeyAuth.Why auth is off by default
The default is
aiGateway.auth.enabled: falseso Tilt andhelm installstill work when no Secret exists.That is convenience. A public LoadBalancer then has no key.
Follow-up: default auth on, or fail install when the Gateway Service is
LoadBalancerand auth is off.Local vs prod
Local and prod use the same Secret shape. Each key is a client id. Each value is an API key.
Helm only stores
existingSecretName. There is no second chart path.Local (Tilt /
make): create the Secret before Helm. A short dummy value is fine for a laptop cluster.You can print
$KEYand send it inx-api-keyon curl. The key can live in Tilt logs.Prod: create the same Secret with a long random value. Use
opensslor a vault.Put the Secret in the cluster. Then give Helm only the Secret name.
Do not put the key in git, in
values.yaml, or in the chart.A dummy string like
replace-meis not for prod.What this does not cover
Test plan
aiGateway.enabled=true,aiGateway.auth.enabled=true, andaiGateway.auth.existingSecretNameto that Secret name.x-api-key. The Gateway must return HTTP 401.x-api-key. The Gateway must not return HTTP 401.