Skip to content

Commit 7f84591

Browse files
committed
docs(auth): clarify gateway mTLS behavior
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
1 parent 3d7786a commit 7f84591

2 files changed

Lines changed: 6 additions & 5 deletions

File tree

‎crates/openshell-core/src/config.rs‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -374,13 +374,13 @@ pub struct OidcConfig {
374374
pub scopes_claim: String,
375375
}
376376

377-
/// mTLS user authentication for local, single-user gateways.
377+
/// mTLS user authentication for gateway users.
378378
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
379379
#[serde(deny_unknown_fields)]
380380
pub struct MtlsAuthConfig {
381381
/// When true, the gateway maps a verified TLS client certificate into a
382-
/// user principal. Keep disabled for Kubernetes deployments because
383-
/// Kubernetes sandbox pods and external users must not share user auth.
382+
/// user principal. Sandbox and supervisor clients use bearer identity, so
383+
/// this setting is independent of the selected compute driver.
384384
#[serde(default)]
385385
pub enabled: bool,
386386
}

‎crates/openshell-server/src/multiplex.rs‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -856,8 +856,9 @@ where
856856
/// Once sandbox authentication is configured, callers must present an
857857
/// explicit credential for authenticated gRPC methods. Missing bearer auth
858858
/// is promoted to an mTLS user only when `mtls_auth.enabled` is configured
859-
/// for local single-user gateways, or to an unsafe local developer user when
860-
/// `auth.allow_unauthenticated_users` is explicitly enabled.
859+
/// and the connection presents a verified client certificate, or to an unsafe
860+
/// local developer user when `auth.allow_unauthenticated_users` is explicitly
861+
/// enabled.
861862
///
862863
/// When neither OIDC nor sandbox credentials are configured (a barebones
863864
/// dev gateway), the chain is left as `None` so the router short-circuits

0 commit comments

Comments
 (0)