Skip to content

Keycloak authentication: one token from CSCS KC for all sites - #115

Draft
rjanalik wants to merge 3 commits into
mainfrom
feature/cscs-keycloak-auth
Draft

rjanalik wants to merge 3 commits into
mainfrom
feature/cscs-keycloak-auth

Conversation

@rjanalik

Copy link
Copy Markdown
Collaborator
  • manta-cli authenticates to CSCS KC to get a token (OIDC code or device flow)
  • no authentication on manta-server
  • prerequisite: CSM KC must trust the CSCS KC

rjanalik and others added 3 commits September 24, 2026 11:21
…ll sites

manta-cli now obtains its bearer token itself over OIDC against the CSCS
Keycloak instead of sending credentials to manta-server's /v2/auth/token.
One token serves every site.

- New common::oidc: browser auth-code + PKCE on a loopback redirect (ID
  token nonce + at_hash verified), device-code flow when headless (config
  `oidc_headless`, or inside an SSH session, or when no browser opens),
  and refresh-token exchange. openidconnect runs over manta-cli's reqwest
  0.13 through a small AsyncHttpClient adapter.
- Token lookup: MANTA_TOKEN env var -> <cache_dir>/token.json (refreshed
  when expired) -> interactive login. No server round-trip; a token the
  site rejects surfaces as a 401 with a hint to re-login.
- New cli.toml keys oidc_issuer_url / oidc_client_id (CSCS defaults; the
  client id and redirect port are placeholders until the Keycloak client
  is registered) and oidc_headless.
- `config unset auth` deletes token.json; legacy <site>_auth files are
  left untouched.

BREAKING CHANGE: MANTA_CSM_TOKEN is renamed to MANTA_TOKEN, and the token
cache moves from per-site <site>_auth files to a single token.json.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MPaEy7U15cDibrbtL2Ei7J
… auditor

The CLI now obtains its token from the CSCS Keycloak directly, so
manta-server no longer handles credentials. The bearer token is still
forwarded unchanged to CSM / Vault / k8s, and the jwt_ops-based
authorization checks are unchanged.

- Drop POST /v2/auth/token and /v2/auth/validate (handlers, service,
  wire types, OpenAPI entries) and the /v2/auth sub-router with its
  per-IP rate limiter and body-redaction middleware.
- Drop the Kafka auditor: its only event was the auth attempt. Removes
  [auditor.kafka], [server].auth_rate_limit_per_minute and rdkafka.
  Existing server.toml files that still set them keep loading; the keys
  are ignored.
- Keep the AuthenticationTrait forwarding in backend_dispatcher so the
  dispatcher-coverage test still holds every trait method to an
  override.
- Regenerate crates/manta-cli/openapi.json.

BREAKING CHANGE: /v2/auth/token and /v2/auth/validate are gone; the
[auditor.kafka] and auth_rate_limit_per_minute settings have no effect.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MPaEy7U15cDibrbtL2Ei7J
Describe the new authentication model everywhere it was documented:
the CLI logs in to the CSCS Keycloak itself (browser + PKCE, device
code when headless, silent refresh), caches one token.json for every
site, and reads MANTA_TOKEN for scripts; manta-server has no /v2/auth
endpoints, rate limiter or Kafka auditor any more.

- README / examples: oidc_* cli.toml keys, token resolution order,
  MANTA_TOKEN, drop auth_rate_limit_per_minute and [auditor.kafka].
- API.md: drop the /auth/* reference and recipes; "Get a token" via the
  CLI's cache.
- ARCHITECTURE.md / SECURITY.md: security model, controls tables,
  middleware diagram, audit trail, sequence diagram.
- GUIDE.md: token-resolution flowchart for scripts.
- MIGRATING.md: new §5.14 plus the v1->v2 sections that described the
  old flow.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MPaEy7U15cDibrbtL2Ei7J

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant