mirror of
https://github.com/agent-substrate/substrate.git
synced 2026-10-02 03:24:42 +08:00
Adds a credential provider for egress credential injection backed by Google Cloud Secret Manager. **It lives in its own Go module under `plugins/gcp-secret-manager`, temporally hosted here until it moves to a repository of its own.** **What it does** - Serves `credproviderpb.CredentialProvider` over mTLS and admits only the egress gateway's identity (`--injector-identity`). - Resolves global and regional secrets, optionally picking one key out of a JSON payload: `ate-secret://secretmanager.googleapis.com/projects/<project>[/locations/<location>]/secrets/<secret>/versions/<version>[/keys/<key>]` - Enforces a default-deny atespace→project policy (`--project-policy-file`), the counterpart of the Kubernetes provider's namespace policy. - Returns a retryable 503 only for transient Secret Manager failures, and caps each read with `--fetch-timeout` (default 3s). **Repository changes** - New top-level `plugins/` directory for self-contained plugins, documented in `docs/dev/code-layout.md` and `AGENTS.md`. The module imports only substrate's public `pkg/` packages; a test enforces this. - CI runs the module's tests, `make verify` and golangci-lint. govulncheck scans the module too, with the action pinned by SHA. - `docs/egress-credential-injection.md` describes each provider's credential URI format. The plugin's README covers installing and using it. - [ ] Tests pass - [ ] Appropriate changes to documentation are included in the PR
43 lines
1.2 KiB
YAML
43 lines
1.2 KiB
YAML
# Copyright 2026 Google LLC
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
name: govulncheck
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
schedule:
|
|
- cron: "37 4 * * 1"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
govulncheck:
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
# The root module, then each module kept apart from it.
|
|
work-dir:
|
|
- .
|
|
- internal/plugins/gcp-secret-manager
|
|
steps:
|
|
- id: govulncheck
|
|
uses: golang/govulncheck-action@032d45514ae346b1db93c04b0c90b841c370344f # v1.1.0
|
|
with:
|
|
go-version-file: go.mod
|
|
go-package: ./...
|
|
work-dir: ${{ matrix.work-dir }}
|