flyio

package
v0.11.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: Apache-2.0 Imports: 17 Imported by: 0

Documentation

Overview

Package flyio provides an OIDC token source and principal extraction for Fly.io Machines, using tokens issued via Fly.io's local metadata socket.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func HasValidClaims added in v0.5.7

func HasValidClaims(claims map[string]any) bool

HasValidClaims reports whether claims contains enough Fly.io-specific fields to be treated as a Fly.io OIDC token validated by a generic JWT middleware. It requires the machine-unique app_id plus at least one additional machine identifier to reduce false positives.

func NewHTTPClient

func NewHTTPClient(ctx context.Context, opts ...Opt) (*http.Client, error)

NewHTTPClient creates an *http.Client that authenticates with a Fly.io OIDC token, fetching one immediately to fail fast on misconfiguration.

func NewTokenSource

func NewTokenSource(opts ...Opt) oauth2.TokenSource

NewTokenSource creates a new token source for Fly.io OIDC tokens, fetched via the local metadata socket. See https://fly.io/docs/security/openid-connect/.

func NewUnixSocketClient

func NewUnixSocketClient(path string) *http.Client

NewUnixSocketClient returns an *http.Client that dials the Unix socket at path regardless of the request's network or address.

Types

type Claims

type Claims struct {
	CustomClaims
}

Claims is the JWT claims type for a Fly.io OIDC token, combining CustomClaims with the auth0/go-jwt-middleware CustomClaims interface.

func (*Claims) ClaimsMap added in v0.8.0

func (c *Claims) ClaimsMap(subject string) map[string]any

ClaimsMap implements oidcutil.ClaimsMapper, flattening the typed Fly.io claims. subject (the token's registered "sub" claim) seeds "username" when present.

func (*Claims) Validate

func (c *Claims) Validate(_ context.Context) error

Validate implements the CustomClaims interface. Fly.io tokens carry no additional claims to validate.

type CustomClaims

type CustomClaims struct {
	// Fly.io specific claims
	AppID          string `json:"app_id"`
	AppName        string `json:"app_name"`
	Image          string `json:"image"`
	ImageDigest    string `json:"image_digest"`
	MachineID      string `json:"machine_id"`
	MachineName    string `json:"machine_name"`
	MachineVersion string `json:"machine_version"`
	OrgID          string `json:"org_id"`
	OrgName        string `json:"org_name"`
	Region         string `json:"region"`
}

CustomClaims represents the custom claims in a Fly.io OIDC token.

type Opt

type Opt func(*tokenSource)

Opt is a function option for configuring the token source.

func WithAudience

func WithAudience(aud string) Opt

WithAudience sets the audience for the OIDC token.

type PrincipalSource added in v0.4.0

type PrincipalSource struct {
	// RoleMapper maps raw Fly.io JWT claims to internal role strings.
	// When nil, Roles returns nil.
	RoleMapper mapper.Mapper
}

PrincipalSource extracts principal identity from Fly.io OIDC tokens.

func (*PrincipalSource) Claims added in v0.4.0

func (s *PrincipalSource) Claims(ctx context.Context) map[string]any

Claims returns the Fly.io token claims as a map. Canonical attribute keys (e.g. "username") are included alongside raw Fly.io claim names so that ClaimRoleMapper rules can reference either form.

func (*PrincipalSource) Extract added in v0.4.0

func (s *PrincipalSource) Extract(ctx context.Context) (string, error)

Extract returns the principal subject from a Fly.io token. It first attempts the typed-claims path (JWT middleware configured with a Fly.io validator), then falls back to fingerprinting generic validated claims stored by a non-typed JWT middleware.

func (*PrincipalSource) IsService added in v0.4.0

func (s *PrincipalSource) IsService(ctx context.Context) bool

IsService returns true for any valid Fly.io token, as these represent machine identities.

func (*PrincipalSource) Name added in v0.4.0

func (s *PrincipalSource) Name() string

Name returns "flyio".

func (*PrincipalSource) Roles added in v0.4.0

func (s *PrincipalSource) Roles(ctx context.Context) []string

Roles returns the internal roles derived from Fly.io claims via the configured RoleMapper. Returns nil when no mapper is set.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL