Skip to content

Send the VenafiConnection's NGTS workspace ID on the token request - #847

Merged
wallrj-cyberark merged 1 commit into
masterfrom
ngts-workspace-id
Oct 9, 2026
Merged

wallrj-cyberark merged 1 commit into
masterfrom
ngts-workspace-id

Conversation

@wallrj-cyberark

@wallrj-cyberark wallrj-cyberark commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

The agent can now use an NGTS Workload Identity Federation (OIDC) service account that belongs to a workspace. Set spec.ngts.workspaceID on the VenafiConnection, and the agent sends it on the token request.

Why now?

NGTS changed how it finds OIDC service accounts. If the token request has no workspace_id, NGTS now only looks at tenant-level accounts. So an OIDC account that lives in a workspace fails with 400 invalid_client "Not found", and the agent cannot use it through a VenafiConnection.

jetstack/venafi-connection-lib#472 added spec.ngts.workspaceID and sends it on the token request. This PR picks that up. Until it is released, you can work around the problem by using a tenant-level service account.

What changes

  • Bump venafi-connection-lib to the jetstack/venafi-connection-lib#472 merge commit (62e2d37). No release contains it yet. We can switch to a tagged version once one is cut.
  • Regenerate the VenafiConnection CRD in both charts. Without the new field in the CRD, the API server drops spec.ngts.workspaceID.
  • Add an NGTS case to the VenafiConnection envtest suite. It checks that workspace_id reaches the token request.

Without workspaceID, nothing changes: the token request has no workspace_id parameter.

Example

A VenafiConnection for an agent whose WIF service account belongs to workspace 1000:

apiVersion: jetstack.io/v1alpha1
kind: VenafiConnection
metadata:
  name: ngts-connection
  namespace: venafi
spec:
  ngts:
    tsgID: "<your-tsgID>"
    workspaceID: "1000" # The workspace that the service account belongs to
    jwt:
    - serviceAccountToken:
        name: workload-identity-sa
        audiences: ["<audience-configured-on-the-service-account>"]

The discovery-agent chart then points at it as usual:

config:
  venafiConnection:
    enabled: true
    name: ngts-connection
    namespace: venafi

Leave workspaceID unset for a tenant-level service account, and for a private key JWT service account.

Please check before merging

The library bump raises k8s.io/* to v0.37.0 and controller-runtime to v0.25.0. venafi-connection-lib's main branch requires them, so Go picks them up automatically.

How this was tested
  • Live NGTS e2e (test-ngts). It passed against a QA tenant, which shows that keypair (private key) auth and uploads still work after the dependency bump. It doesn't use a workspace, so it doesn't exercise the new field.
  • make test-unit: 466 tests pass. The new case TestVenConnClient_PostDataReadingsWithOptions/ngts_with_workspaceID creates a VenafiConnection with workspaceID: "1000". It checks that the NGTS token request carries workspace_id=1000. With the old CRD, the test fails because the API server prunes the unknown field.
  • make verify passes.
  • Not yet tested: a WIF service account in a workspace on a live tenant, through the agent. jetstack/venafi-connection-lib#472 has live tests for that token request. We plan to test the agent with an alpha release after merge.
What this PR deliberately does not do
  • No workspace_id on uploads. NGTS ignores it there: uploads are scoped to the workspace of the service account that authenticated.
  • No --workspace-id flag or config.workspaceID value for keypair mode. NGTS identifies a private-key service account by its client ID and ignores workspace_id, so the option would have no effect.
Generated files
  • The four VenafiConnection CRD copies (two charts, with and without validations) come from make generate. They also pick up other changes made to the library since the previous pin.
  • LICENSES changes come from the dependency bump.

Release note: the agent can use an NGTS Workload Identity Federation service account that belongs to a workspace. Set spec.ngts.workspaceID on the VenafiConnection.

[with Claude]

@wallrj-cyberark
wallrj-cyberark force-pushed the ngts-workspace-id branch 2 times, most recently from 7101f5f to 074b420 Compare October 9, 2026 13:49
@wallrj-cyberark
wallrj-cyberark marked this pull request as ready for review October 9, 2026 13:54
- Bump venafi-connection-lib to pick up spec.ngts.workspaceID. The
  library sends it as the workspace_id query parameter on the NGTS
  token request.
- Regenerate the VenafiConnection CRD in both charts. Without the new
  field in the CRD, the API server drops spec.ngts.workspaceID.
- The library bump also raises k8s.io/* to v0.37.0 and
  controller-runtime to v0.25.0, which venafi-connection-lib requires.

NGTS now only finds an OIDC (workload identity) service account that
lives in a workspace when the token request names that workspace, so
the agent cannot use such an account through a VenafiConnection
without this change.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Richard Wall <richard.wall@cyberark.com>
@wallrj-cyberark wallrj-cyberark changed the title Send the NGTS workspace ID on token requests and uploads Send the VenafiConnection's NGTS workspace ID on the token request Oct 9, 2026

@mladen-rusev-cyberark mladen-rusev-cyberark left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM,

@wallrj-cyberark
wallrj-cyberark merged commit f19ebe1 into master Oct 9, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants