Skip to content

[DLX] Add authentication before scaling resources - #92

Merged
rokatyy merged 3 commits into
v3io:developmentfrom
weilerN:NUC-837-add-auth-before-scale-from-zero
Aug 11, 2026
Merged

rokatyy merged 3 commits into
v3io:developmentfrom
weilerN:NUC-837-add-auth-before-scale-from-zero

Conversation

@weilerN

@weilerN weilerN commented Aug 4, 2026 •

Copy link
Copy Markdown
Collaborator

📝 Description

Add an authentication check in the DLX before scaling a function from zero. The DLX now delegates to a co-located auth-proxy — via a new scalertypes.TargetAuthenticator interface passed in through DLXOptions — before calling startResources, and fails closed: the function stays at zero unless the proxy approves every resolved target for the request.


🛠️ Changes Made

  • Added scalertypes.TargetAuthenticator interface (pkg/scalertypes/types.go), wired into DLXOptions.TargetAuthenticator → NewDLX → NewHandler.
  • Handler.handleRequest now calls AuthenticateTarget(res, req, name) for every resolved target after resolving resourceNames. On any rejection it stops immediately without writing to res — the authenticator has already written the mode-appropriate rejection (401 for api, 302 for browser).
  • Added an InfoWith log ("Resolved targets for request") logging host, path, url, and resourceNames once targets are successfully resolved, plus per-decision Debug logs for auth pass/fail — closes the log-coverage gap raised in nuclio/nuclio#4208 discussion.
  • Added handler_test.go coverage (TestAuthenticateTargetCallback) for the rejection path: asserts SetScaleCtx is never called and the written response status is 401.

✅ Checklist

  • I have tested the changes in this PR

🧪 Testing

  • Unit test added covering the auth-rejection path: a rejectingTargetAuthenticator denies and writes 401; test asserts the DLX doesn't scale (SetScaleCtx not called) and doesn't clobber the authenticator's response.
  • Existing handler test suite (createTestHandlerAndInitTestCache) passes nil authenticator to keep prior behavior covered.
  • Dev test together with the nuclio side

🔗 References


🚨 Breaking Changes?

  • Yes (explain below)
  • No

NewDLX and NewHandler signatures changed (new targetAuthenticator param). Any external caller of these constructors (e.g. nuclio) must be updated to pass a TargetAuthenticator (or nil).


🔍️ Additional Notes

@weilerN
weilerN marked this pull request as ready for review August 9, 2026 17:23
@weilerN weilerN changed the title [DLX] Add authentication before scaling resaources [DLX] Add authentication before scaling resources Aug 10, 2026

@shinil35 shinil35 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice! minor comment

Comment thread pkg/dlx/handler.go Outdated
@weilerN
weilerN requested a review from shinil35 August 10, 2026 14:38
@rokatyy
rokatyy merged commit d80680c into v3io:development Aug 11, 2026
3 checks passed
@weilerN
weilerN deleted the NUC-837-add-auth-before-scale-from-zero branch August 11, 2026 10:46
weilerN added a commit to nuclio/nuclio that referenced this pull request Aug 12, 2026
### 📝 Description
<!-- A short summary of what this PR does. -->
<!-- Include any relevant context or background information. -->
The DLX (scale-to-zero proxy) currently scales a function back up before
any authentication check, so a request that would normally be rejected
by the function's own auth-proxy still triggers a cold start. This PR
adds an authentication step to the DLX itself: before scaling a function
from zero, the DLX asks a co-located `auth-proxy` sidecar (running in
`authOnly` mode) whether the request is allowed, using the same auth
config the function's own auth-proxy would use. If rejected, the DLX
relays the auth-proxy's verdict (401/302/403) to the caller and never
scales the function up.

---

### 🛠️ Changes Made
<!-- - Key changes (e.g., added feature X, refactored Y, fixed Z) -->
- Added `pkg/platform/kube/resourcescaler/targetauthenticator.go`:
`AuthOnlyAuthenticator`, wired into `NuclioResourceScaler.GetConfig()`
as the new `scalertypes.TargetAuthenticator` (from v3io/scaler#92),
gated by `platform.authentication.functionAuthenticationEnabled`. It
forwards the caller's request (relevant headers + request line) to the
DLX-local `auth-proxy` sidecar over loopback and relays the verdict.
- `cmd/authproxy/app/server.go`: the `authOnly` handler now answers on
any path instead of only `/auth`, since the DLX replays the caller's own
request line so browser-mode redirects point back at the URL the caller
actually requested.
- `pkg/auth/authproxy/authonly.go` / `types.go`: removed the now-unused
in-process `bindRequest`/`boundAuthenticator` path and the
`TargetAuthenticator` interface it implemented, superseded by the HTTP
round-trip to the sidecar.
- `hack/k8s/helm/nuclio/templates/deployment/dlx.yaml`: adds the
`auth-proxy` sidecar container to the DLX pod (in `authOnly` mode) when
`functionAuthenticationEnabled` is set.
- Added/updated unit tests: `server_test.go`, `authproxy_test.go`,
`targetauthenticator_test.go`.

---

### ✅ Checklist
- [ ] I updated the documentation (if applicable)
- [x] I have tested the changes in this PR

---

### 🧪 Testing
- UTs
- Dev test - deployed functions with all 3 possible scale to zero modes
(`none`, `api`, `browser`) with minimun 0 replicas, was able to scale
from zero after successful authentication

---

### 🔗 References
- Ticket link: https://ecliptos.atlassian.net/browse/NUC-837
- Design docs links:
- External links: v3io/scaler#92

---

### 🚨 Breaking Changes?

- [ ] Yes (explain below)
- [x] No

<!-- If yes, describe what needs to be changed downstream: -->

---

### 🔍️ Additional Notes
- This PR is blocked by v3io/scaler#92, need a
new DLX tag before merging this code changes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants