You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat: issue token for each kubeconfig on export - #1103
Restore team existence validation before kubeconfig export
src/otomi-stack.ts:2329
The previous implementation validated teamId with getAplTeam before exporting. Without that check, a platform admin can request an arbitrary/nonexistent team ID and still receive a valid team-admin kubeconfig, contrary to this endpoint's team-scoped contract and documented 404 response. Restore the existence check before selecting the namespace.
This issue also appears on line 2339 of the same file.
Added type annotation for sessionUser parameter in getKubecfg method.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Preserve requested team namespace in exported kubeconfig
src/otomi-stack.ts:2335
A platform admin requesting /v1/kubecfg/{teamId} now always receives a config whose current namespace is team-admin, even though the endpoint validates the requested team and names the download for that team; previously it exported team-${teamId}. This makes the exported context target a different namespace than requested. Keep the requested team as the context namespace, and if the admin token must come from team-admin, pass the service-account namespace separately.
Restore validation for missing cluster API server
src/otomi-stack.ts:2346
This removes the previous runtime check for the optional cluster.apiServer setting. Because getSettings is cast to Record<string, any>, a missing value bypasses the string type and produces a downloaded kubeconfig with no server after a token has already been issued. Restore the validation before constructing the generator.
Validate cluster.apiServer before generating kubeconfig
src/otomi-stack.ts:2348
The previous implementation rejected a missing cluster.apiServer, but this now passes undefined into the generator. Because apiServer is optional in src/openapi/cluster.yaml, this can issue a live token and then return a kubeconfig with no server URL. Restore the validation before constructing the generator.
Identify kube-root-ca.crt as a ConfigMap, not a Secret
src/kubecfg.ts:42
This diagnostic calls kube-root-ca.crt a Secret, but the value is read from a ConfigMap. Using the correct resource kind avoids misleading operators investigating the failure.
This issue also appears on line 47 of the same file.
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🔵 Needs a closer look
Invalid token-expiration configuration can pass startup validation and break every kubeconfig export.
Review effort: Balanced Findings: None
Previously missed (2)
In code that hasn't changed since last review
Validate TokenRequest expiration within Kubernetes bounds
src/validators.ts:229
Validate this value as an integer in Kubernetes' accepted TokenRequest range (600 through 2^32 seconds). num also accepts fractional, smaller, and larger values, so a syntactically valid environment setting can make every kubeconfig export fail at the API server instead of failing fast during startup.
Correct diagnostic to identify kube-root-ca.crt as a ConfigMap
src/kubecfg.ts:42
This diagnostic identifies kube-root-ca.crt as a Secret, but the code reads it as a ConfigMap. Naming the actual resource avoids sending operators to inspect the wrong object when CA lookup fails.
Identify kube-root-ca.crt as a ConfigMap, not a Secret
src/kubecfg.ts:42
This diagnostic identifies kube-root-ca.crt as a Secret, but the code reads it as a ConfigMap. Referencing the correct resource kind avoids misleading operators investigating missing CA data.
This issue also appears on line 47 of the same file.
Validate kubeconfig expiration as integer of at least 600 seconds
src/validators.ts:229
Kubernetes rejects TokenRequest lifetimes below 600 seconds and requires this field to be an integer, but num accepts values such as 0, 300, or 600.5. Those configurations pass startup and then make every kubeconfig export fail at the API server. Validate KUBECONFIG_EXPIRATION_SECONDS as an integer of at least 600 during environment parsing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR changes the Kubeconfig generation, creating a token on-demand with a set expiration time.
CA is now inserted for validation if available.