mirror of
https://github.com/agent-substrate/substrate.git
synced 2026-10-02 03:24:42 +08:00
Adds **egress credential injection**: on the sdsmint egress gateway's decrypted MITM leg, when an actor's `EgressPolicy` rule matches and carries an `inject_static_headers` effect, the gateway resolves the referenced credential from a **credential provider** and sets it as a request header (e.g. `Authorization: Bearer <token>`) before re-originating upstream. This implements the `applyEffects` in the egress handler. Injector runs as part of the existing egress ext_proc handler that already fetches/caches/evaluates each actor's `EgressPolicy`, so the MITM leg gains injection without a second ext_proc hop. ### How it works - New `CredentialProvider.FetchSecret` plugin API (`pkg/proto/credproviderpb`): the gateway calls it with the credential URI and the actor's attested SPIFFE identity; the provider authenticates the gateway (mTLS) and resolves the secret. - The egress handler dials the provider over mTLS (`egress.DialProvider`) and injects on matched, allowed requests (`egress.applyEffects`). - Behavior: - **TLS MITM leg + provider configured** → inject the credential (overwriting any actor-set header). - **Cleartext leg, or no provider configured** → skip injection and pass the request through (never put a secret on a cleartext wire; don't block allowed egress). - **Attempted but failed** (unfetchable secret, empty/malformed secret, credential URI of an unserved provider class) → fail closed. ## Installation One flag stands up and wires the whole stack: ``` hack/install-ate.sh --deploy-ate-system --experimental-egress-credential-injection ``` `--experimental-egress-credential-injection` deploys credprovider and the injector, then re-wires the sdsmint egress gateway to route through the injector. It implies `--experimental-use-sdsmint` ### New install flags Two flags configure which credential provider the injector targets: | Flag | Purpose | Default | |---|---|---| | `--credential-provider-name` | Provider class, as a `ate-secret://` prefix; a policy URI of any other class is refused | `ate-secret://kubernetes.io` | | `--credential-provider-address` | Where the injector dials the provider | `credprovider.ate-system.svc:50051` |