identity

package
v0.4.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 21, 2026 License: Apache-2.0 Imports: 6 Imported by: 0

Documentation

Overview

Package identity defines the per-run workload identity contract.

One provider implements it today, with a second planned:

  • embedded (shipped, default): SPIFFE-shaped JWT issuer (sub-ms mint, denylist+TTL revocation, runner-asserted attestation). A strict SPIFFE subset using go-spiffe types — never custom attestation or federation.
  • spire [v0.5 — planned, not yet implemented]: real SPIRE — per-class warm parent entry + per-run child entries, cryptographic node attestation, entry-deletion revocation. No internal/identity/spire package exists yet.

INVARIANT (Confinement gating): cloud STS federation and hostile multi-tenant workloads HARD-REQUIRE the (not-yet-built) spire provider. The embedded provider must refuse to mint identities whose grants include types.GrantCloudSTS.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Names

func Names() []string

Names returns the registered provider names (for /healthz and error messages).

func Register

func Register(name string, c Constructor)

Register adds an identity-provider implementation; call it from an init().

Types

type Claims

type Claims struct {
	// SPIFFEID is spiffe://<trust-domain>/agent-run/<run-id>.
	SPIFFEID string
	RunID    uuid.UUID
	// Sub is the human principal the run acts on behalf of.
	Sub string
	// Sponsor is the accountable human owner (defaults to Sub).
	Sponsor string
	// JTI uniquely identifies this token for revocation/audit join.
	JTI string
	// Audience the token was minted for (RFC 8707 discipline).
	Audience string
	IssuedAt time.Time
	Expiry   time.Time
}

Claims is the verified content of a run identity token. The delegation chain is first-class: Sub is the human principal, Act is the agent run.

type Constructor

type Constructor func(Deps) (Provider, error)

Constructor builds a Provider from Deps.

type Deps

type Deps struct {
	SigningKey  *ecdsa.PrivateKey // embedded signs with this; nil => generated
	TrustDomain string
	Revocations RevocationStore // kill-switch denylist (pg-backed in production)
	Audit       audit.Recorder
	Options     map[string]string // impl-specific config, from WARDYN_IDENTITY_*
}

Deps are the platform primitives an identity.Provider constructor may use. Heterogeneous seams keep their own typed Deps; an impl ignores fields it does not need (e.g. a future SPIRE provider ignores SigningKey, reads Options).

type Provider

type Provider interface {
	// Name returns "embedded" or "spire" — surfaced in UI/audit so the
	// trust boundary is always visible.
	Name() string
	// MintRunIdentity creates the run's identity. audience binds the token.
	MintRunIdentity(ctx context.Context, runID uuid.UUID, humanSub, sponsor, audience string) (RunIdentity, error)
	// Verify authenticates a presented token and returns its claims.
	// Revoked or expired tokens must fail closed.
	Verify(ctx context.Context, token, expectedAudience string) (*Claims, error)
	// RevokeRun invalidates ALL identities for a run (kill-switch cascade).
	RevokeRun(ctx context.Context, runID uuid.UUID) error
}

Provider mints, verifies, and revokes per-run identities.

func New

func New(name string, d Deps) (Provider, error)

New constructs the identity provider selected by name (empty => default).

type RevocationStore

type RevocationStore interface {
	IsRevoked(ctx context.Context, jti string, runID uuid.UUID) (bool, error)
	RevokeRun(ctx context.Context, runID uuid.UUID) error
	RevokeJTI(ctx context.Context, jti string, runID uuid.UUID) error
}

RevocationStore backs the kill-switch denylist for run identities — the generic contract an identity provider's revocation backend satisfies. The pg-backed implementation lives in the control plane (cmd/wardynd); the embedded provider ships an in-memory one for tests.

All read methods MUST fail closed at the call site: a provider treats any IsRevoked error as a revoked token. Revocation is jti-level OR run-level; RevokeRun is the kill-switch cascade (invalidates every current and future token for a run without enumerating jtis).

type RunIdentity

type RunIdentity struct {
	SPIFFEID string
	// Token is the JWT-SVID (or embedded JWT) presented by sidecars and the
	// in-sandbox credential helper when calling the broker.
	Token  string
	JTI    string
	Expiry time.Time
}

RunIdentity is what a provider mints at sandbox start.

Directories

Path Synopsis
Package embedded implements the default, SPIFFE-shaped JWT-SVID identity provider satisfying identity.Provider.
Package embedded implements the default, SPIFFE-shaped JWT-SVID identity provider satisfying identity.Provider.
Package identitytest provides a reusable conformance suite for any identity.Provider implementation, so the blessed default (embedded) and a future alternate (SPIRE) are held to the identical security contract.
Package identitytest provides a reusable conformance suite for any identity.Provider implementation, so the blessed default (embedded) and a future alternate (SPIRE) are held to the identical security contract.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL