feat(egress): add preserve_auth flag to pass agent Authorization through
tracker-policy-pr / check-pr (pull_request) Successful in 6s
test / integration-docker (pull_request) Successful in 13s
test / unit (pull_request) Successful in 35s
lint / lint (push) Successful in 2m28s
test / integration-firecracker (pull_request) Successful in 3m34s
test / coverage (pull_request) Successful in 16s
test / publish-infra (pull_request) Has been skipped
tracker-policy-pr / check-pr (pull_request) Successful in 6s
test / integration-docker (pull_request) Successful in 13s
test / unit (pull_request) Successful in 35s
lint / lint (push) Successful in 2m28s
test / integration-firecracker (pull_request) Successful in 3m34s
test / coverage (pull_request) Successful in 16s
test / publish-infra (pull_request) Has been skipped
Adds a per-route boolean field preserve_auth (default false) that skips the gateway's Authorization header stripping for that host. Intended for registry endpoints like Docker Hub (registry-1.docker.io) and GHCR (ghcr.io) where the agent must supply its own per-scope bearer token. Threaded through ManifestEgressRoute → EgressRoute → Route, serialized in route_to_yaml_dict, and parsed in parse_routes. The strip at egress_addon.py now checks route.preserve_auth before popping the header. Closes #392
This commit is contained in:
@@ -458,6 +458,24 @@ class TestRole(unittest.TestCase):
|
||||
_bottle([{"host": "x.example", "role": ["x", 42]}])
|
||||
|
||||
|
||||
class TestPreserveAuth(unittest.TestCase):
|
||||
def test_omitted_defaults_false(self):
|
||||
b = _bottle([{"host": "registry-1.docker.io"}])
|
||||
self.assertFalse(b.egress.routes[0].PreserveAuth)
|
||||
|
||||
def test_true_accepted(self):
|
||||
b = _bottle([{"host": "registry-1.docker.io", "preserve_auth": True}])
|
||||
self.assertTrue(b.egress.routes[0].PreserveAuth)
|
||||
|
||||
def test_false_accepted(self):
|
||||
b = _bottle([{"host": "registry-1.docker.io", "preserve_auth": False}])
|
||||
self.assertFalse(b.egress.routes[0].PreserveAuth)
|
||||
|
||||
def test_non_bool_rejected(self):
|
||||
with self.assertRaises(ManifestError):
|
||||
_bottle([{"host": "registry-1.docker.io", "preserve_auth": "yes"}])
|
||||
|
||||
|
||||
class TestPipelockKeyRejected(unittest.TestCase):
|
||||
def test_pipelock_key_rejected_as_unknown(self):
|
||||
with self.assertRaises(ManifestError):
|
||||
|
||||
Reference in New Issue
Block a user