Update internal API docs from consumer audit - #5452
Conversation
50929cb to
35a69e3
Compare
stephanme
left a comment
There was a problem hiding this comment.
Maybe we add per endpoint a "Routing" info (internal=port 9023, external=port 9022) so that routing is not implicit from Auth.
In the future, I would move most internal endpoints to internal routing. The access check endpoints should not require external routing but still need OAuth.
The only exceptions should be the download endpoints for local blobstore (needed for staging container). For production (no local blobstore), all internal endpoints should use internal routing.
My comments about changing the url of internal endpoints is for discussion only. This PR documents the current setup.
|
|
||
| ### GET /v2/buildpacks/:guid/download | ||
| **Description:** Download a buildpack file | ||
| **Description:** Download a buildpack file. Note: this is a `/v2` public-namespace path (served on the public listener), not an `/internal/*` endpoint — its `download` action is exempt from user OAuth and gated by staging basic auth instead. |
There was a problem hiding this comment.
This also means: when CF API v2 is disabled, local blobstore is broken.
Future: I suggest to move this endpoint to either /staging/v2/buildpacks/:guid/download or /internal/v2/buildpacks/:guid/download
There was a problem hiding this comment.
Yes, even though the scenario is very unlikely as local blobstore is a dev tool and we don't usually have a working Diego instance running when working locally anyways. But it makes sense to move it in the future as someone could potentially use a local blobstore in a full deployment.
| **Auth Mechanism:** mTLS | ||
| **Auth Mechanism:** Staging basic auth | ||
|
|
||
| ### GET /staging/packages/:guid |
There was a problem hiding this comment.
Future: I would move this endpoint to /internal/staging/packages/:guid or /internal//v2/staging/packages/:guid.
This makes clear that this is an internal API that can be changed/dropped at any point in time.
Add readiness_changed and rescheduling endpoints; fix consumer/auth fields for staging, log_access, asg_latest_update, tasks/completed, metrics, and buildpacks download; add auth-mechanism legend; flag dead-consumer endpoints as removal candidates.
35a69e3 to
7076af2
Compare
Changes in cloud_controller_ng:
- Update internal API docs from consumer audit
PR: cloudfoundry/cloud_controller_ng#5452
Author: Sven Krieger <37476281+svkrieger@users.noreply.github.com>
Add readiness_changed and rescheduling endpoints; fix consumer/auth fields for staging, log_access, asg_latest_update, tasks/completed, metrics, and buildpacks download; add auth-mechanism legend; flag dead-consumer endpoints as removal candidates.
I have reviewed the contributing guide
I have viewed, signed, and submitted the Contributor License Agreement
I have made this pull request to the
mainbranchI have run all the unit tests using
bundle exec rakeI have run CF Acceptance Tests