Skip to content

enterprise/endpoints: use managed connector credentials - #26105

Open
dominic-r wants to merge 26 commits into
dominic/rotation-cloud-providersfrom
dominic/rotation-endpoint-connectors
Open

dominic-r wants to merge 26 commits into
dominic/rotation-cloud-providersfrom
dominic/rotation-endpoint-connectors

Conversation

@dominic-r

@dominic-r dominic-r commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Details

Part of the managed secrets stack, see #25415.

What does this PR change?

Fleet connectors store their API token, and Google Chrome connectors and Device Trust stages their service account keys, as secrets. With no secret_fields users left, the serializer no longer filters them.

Why is this change needed?

Each credential becomes a secret with its own permissions, rotation and audit trail. See #25415.

How was this tested?

Ran the endpoint connector and stage tests, and the secrets and RBAC tests on this layer.

Linked issues


Checklist

  • The project has been linted, built, and tested (make all)
  • The documentation has been updated and formatted (make docs)
  • I have read the AI usage policy.

@dominic-r
dominic-r requested a review from a team as a code owner September 14, 2026 00:46
@dominic-r dominic-r added this to the Release 2026.11.0: Required milestone Sep 14, 2026
@dominic-r
dominic-r requested a review from a team as a code owner September 14, 2026 00:46
@dominic-r dominic-r self-assigned this Sep 14, 2026
@dominic-r
dominic-r added this pull request to stack #26110 September 14, 2026 00:49
@netlify

netlify Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authentik-docs ready!

Name Link
🔨 Latest commit f44f43b
🔍 Latest deploy log https://app.netlify.com/projects/authentik-docs/deploys/6acaaaf36231860008378dcf
😎 Deploy Preview https://deploy-preview-26105--authentik-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from 5152422 to 542605b Compare September 14, 2026 02:02
@codecov

codecov Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

❌ 1 Tests Failed:

Tests completed Failed Passed Skipped
4741 1 4740 14
View the top 1 failed test(s) by shortest run time
600-providers.test.ts::Provider Wizard › Complete OAuth2 Provider
Stack Traces | 92.4s run time
Client Secret should be visible when Client Type is Confidential

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from 542605b to 093794f Compare September 14, 2026 02:18
@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from 093794f to 4690c58 Compare September 14, 2026 02:28
@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from 4690c58 to a9342ca Compare September 14, 2026 02:48
@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from a9342ca to d982492 Compare September 14, 2026 03:32
@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from d982492 to b8736b7 Compare September 14, 2026 04:00
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

authentik PR Installation instructions

Instructions for docker-compose

Add the following block to your .env file:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-dfdcee1d388fc951e66158e8f0ab58cd1a28a60e
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

Afterwards, run the upgrade commands from the latest release notes.

Instructions for Kubernetes

Add the following block to your values.yml file:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-dfdcee1d388fc951e66158e8f0ab58cd1a28a60e

Afterwards, run the upgrade commands from the latest release notes.

…-endpoint-connectors

# Conflicts:
#	authentik/crypto/secrets/api.py
#	packages/client-ts/src/models/AuthenticatorEndpointGDTCStage.ts
#	packages/client-ts/src/models/AuthenticatorEndpointGDTCStageRequest.ts
#	packages/client-ts/src/models/FleetConnector.ts
#	packages/client-ts/src/models/FleetConnectorRequest.ts
#	packages/client-ts/src/models/GoogleChromeConnector.ts
#	packages/client-ts/src/models/GoogleChromeConnectorRequest.ts
#	packages/client-ts/src/models/PatchedAuthenticatorEndpointGDTCStageRequest.ts
#	packages/client-ts/src/models/PatchedFleetConnectorRequest.ts
#	packages/client-ts/src/models/PatchedGoogleChromeConnectorRequest.ts
@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from 636efab to 07f4e77 Compare October 5, 2026 17:57
…-endpoint-connectors

# Conflicts:
#	authentik/core/api/utils.py
#	authentik/crypto/secrets/tests/test_google.py
Google Chrome connector and endpoint stage credentials are JSON secrets
validated by the Secret, which replaces the two validation receivers
that duplicated each other. With no secret_fields left, the serializer
no longer filters them, and the legacy columns stay where they were.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

1 participant