Conversation
rjanalik
commented
Sep 24, 2026
Collaborator
- manta-cli authenticates to CSCS KC to get a token (OIDC code or device flow)
- no authentication on manta-server
- prerequisite: CSM KC must trust the CSCS KC
…ll sites manta-cli now obtains its bearer token itself over OIDC against the CSCS Keycloak instead of sending credentials to manta-server's /v2/auth/token. One token serves every site. - New common::oidc: browser auth-code + PKCE on a loopback redirect (ID token nonce + at_hash verified), device-code flow when headless (config `oidc_headless`, or inside an SSH session, or when no browser opens), and refresh-token exchange. openidconnect runs over manta-cli's reqwest 0.13 through a small AsyncHttpClient adapter. - Token lookup: MANTA_TOKEN env var -> <cache_dir>/token.json (refreshed when expired) -> interactive login. No server round-trip; a token the site rejects surfaces as a 401 with a hint to re-login. - New cli.toml keys oidc_issuer_url / oidc_client_id (CSCS defaults; the client id and redirect port are placeholders until the Keycloak client is registered) and oidc_headless. - `config unset auth` deletes token.json; legacy <site>_auth files are left untouched. BREAKING CHANGE: MANTA_CSM_TOKEN is renamed to MANTA_TOKEN, and the token cache moves from per-site <site>_auth files to a single token.json. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MPaEy7U15cDibrbtL2Ei7J
… auditor The CLI now obtains its token from the CSCS Keycloak directly, so manta-server no longer handles credentials. The bearer token is still forwarded unchanged to CSM / Vault / k8s, and the jwt_ops-based authorization checks are unchanged. - Drop POST /v2/auth/token and /v2/auth/validate (handlers, service, wire types, OpenAPI entries) and the /v2/auth sub-router with its per-IP rate limiter and body-redaction middleware. - Drop the Kafka auditor: its only event was the auth attempt. Removes [auditor.kafka], [server].auth_rate_limit_per_minute and rdkafka. Existing server.toml files that still set them keep loading; the keys are ignored. - Keep the AuthenticationTrait forwarding in backend_dispatcher so the dispatcher-coverage test still holds every trait method to an override. - Regenerate crates/manta-cli/openapi.json. BREAKING CHANGE: /v2/auth/token and /v2/auth/validate are gone; the [auditor.kafka] and auth_rate_limit_per_minute settings have no effect. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MPaEy7U15cDibrbtL2Ei7J
Describe the new authentication model everywhere it was documented: the CLI logs in to the CSCS Keycloak itself (browser + PKCE, device code when headless, silent refresh), caches one token.json for every site, and reads MANTA_TOKEN for scripts; manta-server has no /v2/auth endpoints, rate limiter or Kafka auditor any more. - README / examples: oidc_* cli.toml keys, token resolution order, MANTA_TOKEN, drop auth_rate_limit_per_minute and [auditor.kafka]. - API.md: drop the /auth/* reference and recipes; "Get a token" via the CLI's cache. - ARCHITECTURE.md / SECURITY.md: security model, controls tables, middleware diagram, audit trail, sequence diagram. - GUIDE.md: token-resolution flowchart for scripts. - MIGRATING.md: new §5.14 plus the v1->v2 sections that described the old flow. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MPaEy7U15cDibrbtL2Ei7J
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.