Repository navigation
feat(a2a): read agent credentials from a file or a command - #1550
Merged
Merged
Conversation
Two new credential sources in the auth block of agents.yaml, next to token_env and oidc: - token_file is re-read on every request, so a token rotated in place by the kubelet, spiffe-helper or Vault Agent is picked up. This is the shape a workload gets from its platform and needs no provisioned secret. - token_command runs a cloud CLI or a broker and reuses its stdout until the token expires: the exp claim when it is a JWT, five minutes otherwise. It is honoured from ~/.infer/agents.yaml only, since a project file arrives with a clone and the agent card fetch runs without approval. A failed command is reported by name and exit status, never by its output. oidc gains an optional scopes list, requested on top of the card's. Microsoft Entra ID requires api://<app>/.default on client credentials and the ADK card declares no scopes. Three examples put a mock agent behind Google, Microsoft Entra ID and Amazon Cognito, mirroring the gateway repository's auth-gcp, auth-entra and auth-cognito examples: a2a-auth-gcp and a2a-auth-aws write the provider's token to a file, a2a-auth-entraid runs the client-credentials grant from the oidc block.
4 tasks
Contributor
|
🎉 This PR is included in version 0.227.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two new credential sources in the
authblock ofagents.yaml, next totoken_envandoidc, plus an optionalscopeslist onoidc, and three examples that put an agent behind Google, Microsoft Entra ID and Amazon Cognito.token_fileis re-read on every request, so a token rotated in place by the kubelet, spiffe-helper or Vault Agent is picked up. It is the shape a workload gets from its platform, with no provisioned secret. This is also how kagent carries its workload credential.token_commandruns a cloud CLI or a broker without a shell and reuses its stdout until the token expires (theexpclaim when it is a JWT, five minutes otherwise). It is honoured from~/.infer/agents.yamlonly: a project file arrives with a clone and the agent card fetch runs without approval. A failing command is reported by name and exit status, never by its output.oidc.scopesis requested on top of the card's scopes. Entra requiresapi://<app>/.defaulton client credentials and the ADK card declares none.Why
The existing OIDC handling is spec-correct and ahead of the official A2A SDKs, which only attach a pre-acquired token. What it lacked is a way to use the token a platform or cloud already mints: Google issues ID tokens from the metadata server (no client-credentials grant), Azure managed identity and Entra Agent ID mint tokens by token exchange, Kubernetes and SPIRE hand workloads a token file. Both additions are a few lines in
auth.goand add no dependency.Examples
examples/a2a-auth-gcp,examples/a2a-auth-entraidandexamples/a2a-auth-awsmirror the gateway repository'sauth-gcp,auth-entraandauth-cognitoexamples: a mock agent trusts the provider as its issuer,get-token.shfetches the provider's token, and a tokenless mock model drives the delegation. GCP and AWS usetoken_file, Entra runs the client-credentials grant from theoidcblock.Verification
task precommit:runpasses,go test ./...passes.examples/a2a-auth: all five scenarios pass with this build.examples/a2a-auth-gcpwiring against a static-token mock agent with a hand-written.token: the task completes, a wrong token is reported as an authentication failure.token_commandfrom~/.infer/agents.yamlauthenticatesinfer agents status, the same block in a project.infer/agents.yamlis refused withtoken_command is only read from ~/.infer/agents.yaml.Docs
docs/agents-configuration.md,docs/a2a-connections.mdanddocs/examples.mdare updated here.Docs ticket: inference-gateway/docs#992
Follow-up, not in this PR: native
auth.spiffevia the SPIFFE Workload API, and switchingexamples/a2a-gateway-authfrom a pasted token toauth.oidc.