Documentation
¶
Index ¶
- Constants
- Variables
- func NewDatauploadClient(ctx context.Context, httpClient *http.Client, ...) (*dataupload.CyberArkClient, error)
- func NewRequestAuthenticator(ctx context.Context, httpClient *http.Client, ...) (identity.RequestAuthenticator, error)
- func ValidateJWTSource(source string) error
- type ClientConfig
- type ClientConfigLoader
Constants ¶
const ( // JWTSourceFile is the only currently-supported JWTSource value (besides // the empty string, which also means "file"). JWTSourceFile = "file" // DefaultAccount is the Conjur account name used when ClientConfig.Account // is unset. DefaultAccount = "conjur" )
Variables ¶
var ErrMissingEnvironmentVariables = errors.New("missing environment variables: ARK_SUBDOMAIN")
ErrMissingEnvironmentVariables is returned when required environment variables are not set.
var ErrNoAuthMethod = errors.New("no CyberArk authentication method configured: set config.cyberark.service_id (Conjur JWT) or ARK_USERNAME + ARK_SECRET (legacy username/password)")
ErrNoAuthMethod is returned when neither a Conjur service-id nor username/password credentials are configured.
Functions ¶
func NewDatauploadClient ¶
func NewDatauploadClient(ctx context.Context, httpClient *http.Client, serviceMap *servicediscovery.Services, tenantUUID string, cfg ClientConfig) (*dataupload.CyberArkClient, error)
NewDatauploadClient initializes and returns a new CyberArk Data Upload client. It performs service discovery to find the necessary API endpoints and authenticates using whichever method is configured (Conjur JWT exchange or legacy username/password — see selectAuthenticator).
func NewRequestAuthenticator ¶ added in v1.12.0
func NewRequestAuthenticator(ctx context.Context, httpClient *http.Client, serviceMap *servicediscovery.Services, cfg ClientConfig) (identity.RequestAuthenticator, error)
NewRequestAuthenticator selects and builds the configured request authenticator (Conjur JWT exchange or legacy username/password). Exposed for other consumers (e.g. envelope key fetching) that need the same auth seam without a dataupload client.
func ValidateJWTSource ¶ added in v1.12.0
ValidateJWTSource returns an error if source is set to something other than the empty string or JWTSourceFile — the only supported jwt_source values. Shared so the CLI/config-file validation path and the client construction path can't drift on what's accepted.
Types ¶
type ClientConfig ¶
type ClientConfig struct {
Subdomain string
// Conjur JWT exchange (preferred for new installs).
ServiceID string // authn-jwt service id (POC: per-cluster, e.g. "dev-cluster")
Account string // defaults to DefaultAccount
JWTSource string // "" or JWTSourceFile (POC) | "spiffe" (deferred)
JWTFilePath string // default jwtsource.DefaultTokenPath
// Legacy CyberArk Identity username/password (backward compatibility).
// Sourced from ARK_USERNAME / ARK_SECRET. Used only when ServiceID is unset.
Username string
Secret []byte
}
ClientConfig holds the configuration needed to initialize a CyberArk client.
Two authentication methods coexist (the product is GA; existing installs use username/password). The active method is selected by config presence, see selectAuthenticator: a Conjur authn-jwt ServiceID, when set, takes precedence over username/password.
func LoadClientConfigFromEnvironment ¶
func LoadClientConfigFromEnvironment() (ClientConfig, error)
LoadClientConfigFromEnvironment loads the CyberArk client configuration from environment variables. It expects the following environment variable to be set:
- ARK_SUBDOMAIN: The CyberArk subdomain to use (required).
It also reads the optional legacy username/password credentials:
- ARK_USERNAME, ARK_SECRET: used only when no Conjur service-id is configured.
Behavioral keys (ServiceID, Account, JWTSource, JWTFilePath) are set by the caller from the agent YAML config (config.cyberark.*).
type ClientConfigLoader ¶
type ClientConfigLoader func() (ClientConfig, error)
ClientConfigLoader is a function type that loads and returns a ClientConfig.
Directories
¶
| Path | Synopsis |
|---|---|
|
cmd/testidentity
command
|
|
|
internal/cyberark/jwtsource/jwtsource.go
|
internal/cyberark/jwtsource/jwtsource.go |