Curity Identity Server
Services authenticate with the Curity client they run as.
Services authenticate with the Curity client they run as.
Identity proof
The token has to come from https://login.acme.com/oauth/v2/oauth-anonymous, and its client_id claim has to match the workload you named. We compare that claim byte for byte, with no wildcards.
client_id is matched rather than sub, which on this platform does not name the workload in a form you can pin.
Every token also has to name your workspace as its audience. Ask for this audience and no other. A token requested for two audiences fails every exchange.
Console fields
| Field | Example | Advanced | What it pins |
|---|---|---|---|
| Issuer URL | https://login.acme.com/oauth/v2/oauth-anonymous | no | The issuer of your token profile's discovery document. Must be reachable from the internet. |
| Client ID | penv-deployer | no | Every machine using this client matches. |
The console also asks which project and environment this identity reaches and which role it gets, with the credential lifetime behind Advanced.
Trust
Built from the example answers above:
| What | Value |
|---|---|
| Issuer | https://login.acme.com/oauth/v2/oauth-anonymous |
| Claim compared | client_id |
| Subject | penv-deployer |
| Identity name | curity-penv-deployer |
We name the identity for you, so the form never asks for one.
Console snippet
# Curity: turn on JWT access tokens for the token profile's default token issuer,
# give this client the single audience YOUR_WORKSPACE_ID, and allow it no grant
# but client credentials.
# Ask for this audience and no other. A token requested for two audiences fails every exchange.
# $CURITY_CLIENT_SECRET is this client's own secret, already on the machine.
URL=$(curl -sS <ISSUER>/.well-known/openid-configuration | jq -r .token_endpoint)
T=$(printf 'grant_type=client_credentials&client_id=%s&client_secret=%s' \
"$CURITY_CLIENT_ID" "$CURITY_CLIENT_SECRET" \
| curl -sS "$URL" --data-binary @- | jq -r .access_token)
C=$(curl -sS "https://penv.cloud/api/v1/auth/oidc" \
-H 'content-type: application/json' \
-d "{\"token\":\"$T\"}" | jq -r .credential)
PENV_TOKEN="$C" penv pullThe snippet finishes with penv pull, which writes a file. We recommend penv run for a process; penv pull is for a host that needs a file on disk. Connect your CI has the wrapped step.
Related
- Machine identity
- Connect a Platform in the console
- Curity Identity Server documentation: the subject is the value most often set wrong