Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
feat: Pass optional OIDC audience and issuer through the operator
Follow-up to #6670, requested in review: add audience and issuer to
OidcOptionalSecretProperties so operators can set them in the referenced
OIDC Secret and have them flow into the generated feature_store.yaml auth
section, enabling the new opt-in claim verification on the feature
server. Absent keys change nothing.

Documents the two optional Secret keys in the operator security guide
with a pointer to the OIDC authorization page for the token-claims vs
discovery-metadata caveat.

Signed-off-by: Larry Singleton <166439969+larrysingleton007@users.noreply.github.com>
  • Loading branch information
larrysingleton007 authored and ntkathole committed Jul 31, 2026
commit 28e3609f9c8b764536254d3cc9aa089950dba810
4 changes: 4 additions & 0 deletions docs/how-to-guides/feast-operator/05-security.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,8 +62,12 @@ stringData:
client_secret: <your-client-secret>
username: <service-account-username> # used for client-credentials flow
password: <service-account-password>
audience: <expected-aud-claim> # optional: reject tokens whose aud claim differs
issuer: <expected-iss-claim> # optional: reject tokens whose iss claim differs
```

The optional `audience` and `issuer` keys enable strict claim verification on the feature server; when omitted, only signature and expiry are verified. Set them to the values your IdP puts in the token itself, which are not always the ones in the discovery document (see [OIDC Authorization](../../getting-started/components/authz_manager.md#oidc-authorization)).

Reference the Secret from the CR:

```yaml
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -212,16 +212,20 @@ var _ = Describe("Repo Config", func() {
string(OidcClientId): clientIDValue,
string(OidcClientSecret): "client-secret",
string(OidcUsername): "username",
string(OidcPassword): "password"})
string(OidcPassword): "password",
string(OidcAudience): "api://feast-feature-server",
string(OidcIssuer): "https://login.example.com/realms/master"})
repoConfig, err = getServiceRepoConfig(featureStore, secretExtractionFunc, emptyMockExtractConfigFromConfigMap, false)
Expect(err).NotTo(HaveOccurred())
Expect(repoConfig.AuthzConfig.Type).To(Equal(OidcAuthType))
Expect(repoConfig.AuthzConfig.OidcParameters).To(HaveLen(5))
Expect(repoConfig.AuthzConfig.OidcParameters).To(HaveLen(7))
Expect(repoConfig.AuthzConfig.OidcParameters).To(HaveKey(string(OidcClientId)))
Expect(repoConfig.AuthzConfig.OidcParameters).To(HaveKey(string(OidcAuthDiscoveryUrl)))
Expect(repoConfig.AuthzConfig.OidcParameters).To(HaveKey(string(OidcClientSecret)))
Expect(repoConfig.AuthzConfig.OidcParameters).To(HaveKey(string(OidcUsername)))
Expect(repoConfig.AuthzConfig.OidcParameters).To(HaveKey(string(OidcPassword)))
Expect(repoConfig.AuthzConfig.OidcParameters).To(HaveKeyWithValue(string(OidcAudience), "api://feast-feature-server"))
Expect(repoConfig.AuthzConfig.OidcParameters).To(HaveKeyWithValue(string(OidcIssuer), "https://login.example.com/realms/master"))
Expect(repoConfig.OfflineStore).To(Equal(expectedOfflineConfig))
Expect(repoConfig.OnlineStore).To(Equal(defaultOnlineStoreConfig(featureStore)))
Expect(repoConfig.Registry).To(Equal(defaultRegistryConfig(featureStore)))
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,8 @@ const (
OidcTokenEnvVar OidcPropertyType = "token_env_var"
OidcVerifySsl OidcPropertyType = "verify_ssl"
OidcCaCertPath OidcPropertyType = "ca_cert_path"
OidcAudience OidcPropertyType = "audience"
OidcIssuer OidcPropertyType = "issuer"

OidcMissingSecretError string = "missing OIDC secret: %s"

Expand Down Expand Up @@ -274,7 +276,7 @@ var (
},
}

OidcOptionalSecretProperties = []OidcPropertyType{OidcAuthDiscoveryUrl, OidcClientId, OidcClientSecret, OidcUsername, OidcPassword}
OidcOptionalSecretProperties = []OidcPropertyType{OidcAuthDiscoveryUrl, OidcClientId, OidcClientSecret, OidcUsername, OidcPassword, OidcAudience, OidcIssuer}
)

// Feast server types: Reserved only for server types like Online, Offline, and Registry servers. Should not be used for client types like the UI, etc.
Expand Down