servicediscovery

package
v1.12.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 23 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// ProdDiscoveryAPIBaseURL is the base URL for the production CyberArk Service Discovery API
	ProdDiscoveryAPIBaseURL = "https://platform-discovery.cyberark.cloud/"

	// IdentityServiceName is the name of the identity service we're looking for in responses from the Service Discovery API
	// We were told to use the identity_administration field, not the identity_user_portal field.
	IdentityServiceName = "identity_administration"

	// DiscoveryContextServiceName is the name of the discovery and context API
	// in responses from the Service Discovery API.
	DiscoveryContextServiceName = "discoverycontext"

	// SecretsManagerServiceName is the name of the Secrets Manager (Conjur
	// Cloud) API in responses from the Service Discovery API. This is the host
	// that serves `authn-jwt/<service-id>/<account>/authenticate` — NOT the
	// identity_administration host. The server that validates the resulting
	// token resolves this same service name.
	SecretsManagerServiceName = "secrets_manager"
)
View Source
const (
	// MockDiscoverySubdomain is the subdomain for which the MockDiscoveryServer will return a success response
	MockDiscoverySubdomain = "tlskp-test"
)

Variables

This section is empty.

Functions

func MockDiscoveryServer

func MockDiscoveryServer(t testing.TB, services Services) *http.Client

MockDiscoveryServer starts a mocked CyberArk service discovery server and returns an HTTP client with the CA certs needed to connect to it.

The URL of the mock server is set in the `ARK_DISCOVERY_API` environment variable, so any code using the `servicediscovery.Client` will use this mock server.

The mock server will return a successful response when the subdomain is `MockDiscoverySubdomain`, and the API URLs in the response will match those supplied in `services`. Other subdomains, can be used to trigger various failure responses.

Sets allowLoopbackHosts for the duration of the test, so DiscoverServices' allowlist accepts these loopback mocks. Deliberately invalid test hosts (attacker.example, plain http://) are unaffected and still rejected.

The returned HTTP client has a transport which logs requests and responses depending on log level of the logger supplied in the context.

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client is a Golang client for interacting with the CyberArk Discovery Service. It allows users to fetch URLs for various APIs available in CyberArk. This client is specialised to fetch only API endpoints, since only API endpoints are required by the Venafi Kubernetes Agent currently.

func New

func New(httpClient *http.Client, subdomain string) (*Client, error)

New creates a new CyberArk Service Discovery client. If the ARK_DISCOVERY_API environment variable is set, it is used as the base URL for the service discovery API. Otherwise, the production URL is used.

The base URL is validated here so that a bad ARK_DISCOVERY_API is reported as the configuration error it is, at startup, rather than surfacing later as a repeating push failure.

func (*Client) DiscoverServices

func (c *Client) DiscoverServices(ctx context.Context) (*Services, string, error)

DiscoverServices fetches from the service discovery service for the configured subdomain and parses the CyberArk Identity API URL and Inventory API URL. It also returns the Tenant ID UUID corresponding to the subdomain.

type DiscoveryResponse

type DiscoveryResponse struct {
	Region      string         `json:"region"`
	DRRegion    string         `json:"dr_region"`
	Subdomain   string         `json:"subdomain"`
	TenantID    string         `json:"tenant_id"`
	PlatformID  string         `json:"platform_id"`
	IdentityID  string         `json:"identity_id"`
	DefaultURL  string         `json:"default_url"`
	TenantFlags map[string]any `json:"tenant_flags"`
	Services    []Service      `json:"services"`
}

DiscoveryResponse represents the full JSON response returned by the CyberArk api/tenant-discovery/public API The API is documented here https://ca-il-confluence.il.cyber-ark.com/spaces/EV/pages/575618345/Updated+PD+APIs+doc

type Service

type Service struct {
	ServiceName       string            `json:"service_name"`
	ServiceSubdomains []string          `json:"service_subdomains"`
	Region            string            `json:"region"`
	Endpoints         []ServiceEndpoint `json:"endpoints"`
}

type ServiceEndpoint

type ServiceEndpoint struct {
	IsActive bool   `json:"is_active"`
	Type     string `json:"type"`
	UI       string `json:"ui"`
	API      string `json:"api"`
}

ServiceEndpoint represents a single service endpoint returned by the CyberArk Service Discovery API. The JSON field names here must match the field names returned by the Service Discovery API.

type Services

type Services struct {
	Identity         ServiceEndpoint
	DiscoveryContext ServiceEndpoint
	SecretsManager   ServiceEndpoint
}

This is a convenience struct to hold the ServiceEndpoints we care about: the Identity API, the Discovery Context API, and the Secrets Manager (Conjur Cloud) API used for the authn-jwt token exchange.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL