fix: add more cached certificates to azure instance identity (#6519)

This was failing for GovCloud. Now it falls back to fetch, and a test
has been added to notify when certificates are becoming outdated.
This commit is contained in:
Kyle Carberry
2023-03-08 19:32:10 -06:00
committed by GitHub
parent 54bbed8c3c
commit d67552f852
3 changed files with 264 additions and 17 deletions
+3 -1
View File
@@ -37,7 +37,9 @@ func (api *API) postWorkspaceAuthAzureInstanceIdentity(rw http.ResponseWriter, r
if !httpapi.Read(ctx, rw, r, &req) {
return
}
instanceID, err := azureidentity.Validate(req.Signature, api.AzureCertificates)
instanceID, err := azureidentity.Validate(r.Context(), req.Signature, azureidentity.Options{
VerifyOptions: api.AzureCertificates,
})
if err != nil {
httpapi.Write(ctx, rw, http.StatusUnauthorized, codersdk.Response{
Message: "Invalid Azure identity.",