Authenticate in the other direction with jwtproxy

This commit is contained in:
Evan Cordell 2016-04-21 15:27:00 -05:00 committed by Jimmy Zelinskie
parent da0a988650
commit 9e7a501dae
4 changed files with 17 additions and 3 deletions

View file

@ -3,6 +3,6 @@
echo 'Starting jwtproxy'
cd /
/binary_dependencies/jwtproxy --config conf/jwtproxy_conf.yaml
/binary_dependencies/jwtproxy --config conf/jwtproxy_conf.yaml --log-level debug
echo 'Jwtproxy exited'

View file

@ -1,6 +1,18 @@
jwtproxy:
signer_proxy:
enabled: false
enabled: true
listen_addr: :8080
signer:
issuer: quay
expiration_time: 5m
max_skew: 1m
private_key:
type: autogenerated
options:
key_server:
type: keyregistry
options:
registry: {{ registry }}
verifier_proxy:
enabled: true
listen_addr: unix:/tmp/jwtproxy_secscan.sock

View file

@ -288,6 +288,7 @@ class DefaultConfig(object):
'API_VERSION': 'v1',
'API_TIMEOUT_SECONDS': 10,
'API_TIMEOUT_POST_SECONDS': 480,
'PROXY': 'http://localhost:8080',
}
# Torrent management flags

View file

@ -257,4 +257,5 @@ class SecurityScannerAPI(object):
with CloseForLongOperation(self.config):
logger.debug('%sing security URL %s', method.upper(), url)
return client.request(method, url, json=body, params=params, timeout=timeout,
cert=self._keys, verify=self._certificate, headers=headers)
cert=self._keys, verify=self._certificate, headers=headers,
proxies=security_config.get('PROXY'))