Skip to content

cli: add flyte auth token to print the current access token - #1616

Draft
mhotan wants to merge 5 commits into
mainfrom
mike/flyte-auth-token
Draft

mhotan wants to merge 5 commits into
mainfrom
mike/flyte-auth-token

Conversation

@mhotan

@mhotan mhotan commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Adds a flyte auth group with a token subcommand that prints the CLI's current access token to stdout. It reuses the authenticator the rest of the CLI uses (endpoint, auth mode, TLS settings) and refreshes when the cached token is missing, expired or within 120s of expiry. If the token can't be parsed, it refreshes rather than print it.

This lets tools pass a Flyte identity inline without writing credentials to disk, e.g. querying a Flyte-authorized endpoint with kubectl:

KUBECONFIG=/dev/null kubectl --server="https://<app>.apps.<domain>" --token="$(flyte auth token)" get pods

(KUBECONFIG=/dev/null stops kubectl from applying the current context's CA to that server.)

The token goes to stdout only and is never logged. --format=exec-credential is left for a follow-up. Unit tests cover the expiry check and the command wiring.

🤖 Generated with Claude Code

https://claude.ai/code/session_01L3kDaivS287GLUJSPkeY6h

@mhotan
mhotan force-pushed the mike/flyte-auth-token branch from 093b3c7 to 1f6fa9c Compare September 24, 2026 04:45
Adds a small `flyte auth` group with a `token` subcommand that prints the CLI's
current Union access token to stdout, reusing the same authenticator the rest of
the CLI uses (endpoint, auth mode, TLS posture) so it stays in lockstep. It
refreshes when the cached token is missing, expired, or within 120s of expiry,
and fails safe (refreshes) on an unparseable token.

This unblocks stateless inline execution against the read-only in-cluster kubectl
proxy without any files on disk:

    kubectl --server="https://union-k8s-ro.apps.<dp>.<domain>" \
            --token="$(flyte auth token)" get pods -A

The token is written to stdout only and never logged. (`--format=exec-credential`
is deferred.)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L3kDaivS287GLUJSPkeY6h

Signed-off-by: Michael Hotan <mike@union.ai>
@mhotan
mhotan force-pushed the mike/flyte-auth-token branch from 1f6fa9c to 189cb5c Compare September 25, 2026 06:13
mhotan and others added 4 commits September 29, 2026 07:14
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L3kDaivS287GLUJSPkeY6h
Signed-off-by: Michael Hotan <mike@union.ai>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L3kDaivS287GLUJSPkeY6h
Signed-off-by: Michael Hotan <mike@union.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant