Skip to content

[RFC-XXXX] Vendor-Agnostic Short-Lived Credentials - #5702

Open
matheuscscp wants to merge 2 commits into
mainfrom
rfc-creds
Open

[RFC-XXXX] Vendor-Agnostic Short-Lived Credentials#5702
matheuscscp wants to merge 2 commits into
mainfrom
rfc-creds

Conversation

@matheuscscp

@matheuscscp matheuscscp commented Feb 2, 2026

Copy link
Copy Markdown
Member

@matheuscscp
matheuscscp requested a review from a team February 2, 2026 01:41
@matheuscscp matheuscscp added enhancement New feature or request area/security Security related issues and pull requests area/oci OCI related issues and pull requests labels Feb 2, 2026
@matheuscscp
matheuscscp force-pushed the rfc-creds branch 4 times, most recently from 87c0172 to e2a8a56 Compare February 2, 2026 02:13
Comment thread rfcs/xxxx-vendor-agnostic-short-lived-credentials/README.md Outdated
@matheuscscp
matheuscscp force-pushed the rfc-creds branch 2 times, most recently from 4adaa54 to 635872b Compare February 2, 2026 13:59
Comment thread rfcs/xxxx-vendor-agnostic-short-lived-credentials/README.md
Comment on lines +83 to +84
short-lived credential to use for authentication. The field is mutually exclusive
with `.spec.provider` (when set to a cloud provider) because "provider" conveys

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we provide another CEL rule example for this? Given "mutual exclusivity".

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not sure I follow the suggestion 🤔

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the current CEL expression already covers the entire mutual exclusivity, no? 🤔

Comment thread rfcs/xxxx-vendor-agnostic-short-lived-credentials/README.md Outdated
Comment thread rfcs/xxxx-vendor-agnostic-short-lived-credentials/README.md Outdated
@matheuscscp
matheuscscp force-pushed the rfc-creds branch 2 times, most recently from f9632fd to 792631f Compare February 3, 2026 18:08
@matheuscscp

matheuscscp commented Feb 3, 2026

Copy link
Copy Markdown
Member Author

@hiddeco I fixed the inconsistencies you found around the SPIFFE flags in this diff: https://github.com/fluxcd/flux2/compare/f9632fd9d7c118763ba7bfbd2e88cbe8a9dbf8e3..792631f49699aa8813cc24f2875f3a75fe1a826c

They were an artifact of my late decision to introduce a separate flag for the trust domain.

Signed-off-by: Matheus Pimenta <matheuscscp@gmail.com>
Signed-off-by: Matheus Pimenta <matheuscscp@gmail.com>
Comment thread rfcs/xxxx-vendor-agnostic-short-lived-credentials/README.md
@matheuscscp

Copy link
Copy Markdown
Member Author

@stefanprodan @hiddeco @stealthybox The last week to work on ServiceAccountToken for Flux 2.8 is the next one, let's try to approve this RFC ASAP 🙏

Comment thread rfcs/xxxx-vendor-agnostic-short-lived-credentials/README.md
@matheuscscp

Copy link
Copy Markdown
Member Author

As explained here: #5702 (comment)

The SPIFFE integration currently described in this proposal is stale. This RFC will soon undergo lots of changes.

Also, this RFC is delayed to Flux 2.10 (planned for somewhere in Q4), and it will be the main topic of the release. The Flux 2.9 release is unfortunately coming very soon: we will start releasing the controllers on June 15. Flux 2.9 is also very stuffed and even if we had more time we decided not to ship more things, otherwise the time we planned for dealing with fallouts and bugs after the release will not be enough and we will compromise other things in our calendars.

cc @vicaya

@matheuscscp

Copy link
Copy Markdown
Member Author

SPIFFE merged the Broker API today!

spiffe/spiffe#340

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/oci OCI related issues and pull requests area/rfc Feature request proposals in the RFC format area/security Security related issues and pull requests enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[RFC-XXXX] Vendor-Agnostic Short-Lived Credentials

6 participants