Conversation
wan9chi
added this pull request to stack #799
October 4, 2026 07:52
The plan now resolves how remote cache requests authenticate, alongside the access mode and endpoint, into `ResolvedRemoteCacheConfig::auth`. It holds everything needed to build the credentials, so nothing reads envs after planning: - `anonymous`: no credentials. - `github-oidc`: chosen when `ACTIONS_ID_TOKEN_REQUEST_URL` and `ACTIONS_ID_TOKEN_REQUEST_TOKEN` are set. Stores carry a GitHub Actions OIDC token whose audience is the endpoint without a trailing slash. The request token is a `Secret`, which debug output and serialized plans redact. `vt` builds the `vt_remote_cache::auth::Auth` for a config with one match, and caches clients by endpoint and auth. `GithubOidc` requests a token when the first store needs it, reuses it until two minutes before it expires, shares one request between concurrent stores, and remembers a failed request, so later stores fail without another one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
wan9chi
force-pushed
the
claude/github-oidc-auth-headers-18e511
branch
from
October 4, 2026 07:52
3f44ec4 to
64b0977
Compare
fspy benchmarklinuxmacoswindows |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The self-hosted remote cache server in #718, designed in #716, accepts uploads only with a GitHub Actions OIDC token. The token's audience must be the namespace endpoint, and it must come from a push job on the main branch.
vp runsends stores without credentials today, so that server rejects every upload with 401.Changes
remote_cache.auth, along with the access mode and endpoint. It uses the envs visible at eachvp runlevel, and the result holds everything needed to build the credentials. Nothing reads envs after planning.anonymous: no credentials. This is the default.github-oidc: chosen whenACTIONS_ID_TOKEN_REQUEST_URLandACTIONS_ID_TOKEN_REQUEST_TOKENare set, which happens in jobs withpermissions: id-token: write. It holds the request URL, the request token, and the audience, which is the endpoint without a trailing slash. The request token is aSecret, which debug output and serialized plans redact.cache.remoteconfig later only changes this step.vtturns the resolved auth into avt_remote_cacheauth with onematch, and caches clients by endpoint and auth.vt_remote_cache::auth::GithubOidcaddsAuthorization: Bearer <token>to stores only. Fetches and downloads stay anonymous.exp, because the server can take up to two minutes to finish a store.vp runkeeps working.Stacked on #797, which adds the
Authhook.🤖 Generated with Claude Code