agent-substrate / agent-substrate/substrate

[Feature] Actor Identity

オープン
#124 コメント 4 件 リアクション 0 件 担当者 1 名 @ahmedtd が担当を希望しています GitHub で見る
area/identity area/node area/security kind/feature prio/P0
主要言語
Go
スター
1.8k
フォーク
316
平均マージ
2日 43分
マージ済み PR(30日)
287

説明

For Alpha, we need to give Actors access to OIDC JWTs and SPIFFE certificates issued by substrate. We already have the broker RPCs implemented, but we have the following open items:

* How do we expose the credentials into the Actor (filesystem mounts, metadata server, vsock)?
* Formalize the claims in each credential.
* Make atelet/ateom use the actor credentials for snapshot storage / retrieval.
* (For GCP) Prove out federation of the substrate IDP back to GCP, and demonstrate how it can be used against GCS.

## Basic design

The substrate control plane includes a broker API, where a caller can exchange a K8s-layer credential (service account JWT or service account certificate) for a substrate JWT / certificate.

The substrate credential will carry at least the following claims:
* Actor Template Namespace
* Actor Template Name
* Actor ID

These credentials will be federatable, and so should be able to be used against GCS, S3, and other cloud provider services. They could also be used for actor-to-actor authentication, and general actor-to-service authentication.

## (GCP-specific) Federation

Both OIDC JWTs and SPIFFE certificates can be federated into GCP IAM using Workload Identity Federation.

While it will not be scalable to create and delete per-actor IAM policies for each actor, it should be possible to use IAM conditions to write a single policy that authorizes every actor to access their own data. For example, "all callers from substrate issuer X have storage/object.admin on GCS bucket Y, as long as the object path starts with `actors/${ate.dev/actor-id}`".

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。