Repository navigation
[DLX] Add authentication before scaling resources - #92
Merged
rokatyy merged 3 commits intoAug 11, 2026
Merged
Conversation
2 of 4 tasks
weilerN
marked this pull request as ready for review
August 9, 2026 17:23
shinil35
approved these changes
Aug 11, 2026
weilerN
added a commit
to nuclio/nuclio
that referenced
this pull request
Aug 12, 2026
### 📝 Description <!-- A short summary of what this PR does. --> <!-- Include any relevant context or background information. --> The DLX (scale-to-zero proxy) currently scales a function back up before any authentication check, so a request that would normally be rejected by the function's own auth-proxy still triggers a cold start. This PR adds an authentication step to the DLX itself: before scaling a function from zero, the DLX asks a co-located `auth-proxy` sidecar (running in `authOnly` mode) whether the request is allowed, using the same auth config the function's own auth-proxy would use. If rejected, the DLX relays the auth-proxy's verdict (401/302/403) to the caller and never scales the function up. --- ### 🛠️ Changes Made <!-- - Key changes (e.g., added feature X, refactored Y, fixed Z) --> - Added `pkg/platform/kube/resourcescaler/targetauthenticator.go`: `AuthOnlyAuthenticator`, wired into `NuclioResourceScaler.GetConfig()` as the new `scalertypes.TargetAuthenticator` (from v3io/scaler#92), gated by `platform.authentication.functionAuthenticationEnabled`. It forwards the caller's request (relevant headers + request line) to the DLX-local `auth-proxy` sidecar over loopback and relays the verdict. - `cmd/authproxy/app/server.go`: the `authOnly` handler now answers on any path instead of only `/auth`, since the DLX replays the caller's own request line so browser-mode redirects point back at the URL the caller actually requested. - `pkg/auth/authproxy/authonly.go` / `types.go`: removed the now-unused in-process `bindRequest`/`boundAuthenticator` path and the `TargetAuthenticator` interface it implemented, superseded by the HTTP round-trip to the sidecar. - `hack/k8s/helm/nuclio/templates/deployment/dlx.yaml`: adds the `auth-proxy` sidecar container to the DLX pod (in `authOnly` mode) when `functionAuthenticationEnabled` is set. - Added/updated unit tests: `server_test.go`, `authproxy_test.go`, `targetauthenticator_test.go`. --- ### ✅ Checklist - [ ] I updated the documentation (if applicable) - [x] I have tested the changes in this PR --- ### 🧪 Testing - UTs - Dev test - deployed functions with all 3 possible scale to zero modes (`none`, `api`, `browser`) with minimun 0 replicas, was able to scale from zero after successful authentication --- ### 🔗 References - Ticket link: https://ecliptos.atlassian.net/browse/NUC-837 - Design docs links: - External links: v3io/scaler#92 --- ### 🚨 Breaking Changes? - [ ] Yes (explain below) - [x] No <!-- If yes, describe what needs to be changed downstream: --> --- ### 🔍️ Additional Notes - This PR is blocked by v3io/scaler#92, need a new DLX tag before merging this code changes
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📝 Description
Add an authentication check in the DLX before scaling a function from zero. The DLX now delegates to a co-located auth-proxy — via a new
scalertypes.TargetAuthenticatorinterface passed in throughDLXOptions— before callingstartResources, and fails closed: the function stays at zero unless the proxy approves every resolved target for the request.🛠️ Changes Made
scalertypes.TargetAuthenticatorinterface (pkg/scalertypes/types.go), wired intoDLXOptions.TargetAuthenticator→NewDLX→NewHandler.Handler.handleRequestnow callsAuthenticateTarget(res, req, name)for every resolved target after resolvingresourceNames. On any rejection it stops immediately without writing tores— the authenticator has already written the mode-appropriate rejection (401 for api, 302 for browser).InfoWithlog ("Resolved targets for request") logginghost,path,url, andresourceNamesonce targets are successfully resolved, plus per-decisionDebuglogs for auth pass/fail — closes the log-coverage gap raised in nuclio/nuclio#4208 discussion.handler_test.gocoverage (TestAuthenticateTargetCallback) for the rejection path: assertsSetScaleCtxis never called and the written response status is401.✅ Checklist
🧪 Testing
rejectingTargetAuthenticatordenies and writes401; test asserts the DLX doesn't scale (SetScaleCtxnot called) and doesn't clobber the authenticator's response.createTestHandlerAndInitTestCache) passesnilauthenticator to keep prior behavior covered.🔗 References
🚨 Breaking Changes?
NewDLXandNewHandlersignatures changed (newtargetAuthenticatorparam). Any external caller of these constructors (e.g. nuclio) must be updated to pass aTargetAuthenticator(ornil).🔍️ Additional Notes