apache / apache/openwhisk-deploy-kube

Invoking action gives 403: Trigger authentication request failed

Open
#773 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
309
Forks
231
PR merge metrics
No merged PRs in 30d

Description

I have openwhisk deployed on a kubernetes cluster. I created a trigger called once-per-minute using this swagger ui,
The curl request: -
```
curl -X PUT "https://localhost:4430/api/v1/namespaces/_/triggers/once-per-min?overwrite=false" -H "accept: application/json" -H "authorization: Basic Nzg5YzQ2YjEtNzFmNi00ZWQ1LThjNTQtODE2YWE0ZjhjNTAyOmFiY3pPM3haQ0xyTU42djJCS0sxZFhZRnBYbFBrY2NPRnFtMTJDZEFzTWdSVTRWck5aOWx5R1ZDR3VNREdJd1A=" -H "Content-Type: application/json" -d "{\"name\":\"once-per-min\",\"annotations\":[{\"key\":\"feed\",\"value\":\"/whisk.system/alarms/alarm\"}]}"
```
Got Response 200
```
{
"annotations": [
{
"key": "feed",
"value": "/whisk.system/alarms/alarm"
}
],
"limits": {},
"name": "once-per-min",
"namespace": "whisk.system",
"parameters": [],
"publish": false,
"updated": 1703607489753,
"version": "0.0.1"
}
```

Now, I tried to create a cron job for the alarm action in whisk.system
```
curl -X POST "https://localhost:4430/api/v1/namespaces/whisk.system%2Falarms/actions/alarm?blocking=true&result=false" -H "accept: application/json" -H "authorization: Basic Nzg5YzQ2YjEtNzFmNi00ZWQ1LThjNTQtODE2YWE0ZjhjNTAyOmFiY3pPM3haQ0xyTU42djJCS0sxZFhZRnBYbFBrY2NPRnFtMTJDZEFzTWdSVTRWck5aOWx5R1ZDR3VNREdJd1A=" -H "Content-Type: application/json" -d "{\"authKey\":\"23bc46b1-71f6-4ed5-8c54-816aa4f8c502:123zO3xZCLrMN6v2BKK1dXYFpXlPkccOFqm12CdAsMgRU4VrNZ9lyGVCGuMDGIwP\",\"cron\":\"*/1 * * * *\",\"lifecycleEvent\":\"CREATE\",\"triggerName\":\"/_/once-per-min\"}"
```
Got a 502 bad gateway
```
{
"activationId": "260396828cb84c158396828cb82c15b7",
"annotations": [
{
"key": "path",
"value": "whisk.system/alarms/alarm"
},
{
"key": "waitTime",
"value": 13
},
{
"key": "kind",
"value": "nodejs:10"
},
{
"key": "timeout",
"value": false
},
{
"key": "limits",
"value": {
"concurrency": 1,
"logs": 10,
"memory": 256,
"timeout": 60000
}
}
],
"duration": 38,
"end": 1703607625061,
"logs": [],
"name": "alarm",
"namespace": "whisk.system",
"publish": false,
"response": {
"result": {
"error": {
"error": "Trigger authentication request failed."
}
},
"size": 60,
"status": "application error",
"success": false
},
"start": 1703607625023,
"subject": "whisk.system",
"version": "0.0.1"
}
```

Tried to read the activation
```
{
"activationId": "260396828cb84c158396828cb82c15b7",
"annotations": [
{
"key": "path",
"value": "whisk.system/alarms/alarm"
},
{
"key": "waitTime",
"value": 13
},
{
"key": "kind",
"value": "nodejs:10"
},
{
"key": "timeout",
"value": false
},
{
"key": "limits",
"value": {
"concurrency": 1,
"logs": 10,
"memory": 256,
"timeout": 60000
}
}
],
"duration": 38,
"end": 1703607625061,
"logs": [
"2023-12-26T16:20:25.061306357Z stdout: alarm: Error invoking whisk action: 403 { error: 'Trigger authentication request failed.' }"
],
"name": "alarm",
"namespace": "whisk.system",
"publish": false,
"response": {
"result": {
"error": {
"error": "Trigger authentication request failed."
}
},
"size": 60,
"status": "application error",
"success": false
},
"start": 1703607625023,
"subject": "whisk.system",
"version": "0.0.1"
}
```

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the trigger creation and alarm action requests shown in the issue, then inspect the activation log containing the 403 error. Trace the Kubernetes deployment configuration and OpenWhisk alarm invocation path to identify the authentication failure. Done means the scheduled trigger invokes the alarm action successfully without the authentication error.

Written by the indexing model from the issue text.

Assessment

Tech stack
kubernetes, shell
Domain
api, cloud, infrastructure
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.