Conversation
mhotan
force-pushed
the
mike/flyte-auth-token
branch
from
September 24, 2026 04:45
093b3c7 to
1f6fa9c
Compare
Adds a small `flyte auth` group with a `token` subcommand that prints the CLI's
current Union access token to stdout, reusing the same authenticator the rest of
the CLI uses (endpoint, auth mode, TLS posture) so it stays in lockstep. It
refreshes when the cached token is missing, expired, or within 120s of expiry,
and fails safe (refreshes) on an unparseable token.
This unblocks stateless inline execution against the read-only in-cluster kubectl
proxy without any files on disk:
kubectl --server="https://union-k8s-ro.apps.<dp>.<domain>" \
--token="$(flyte auth token)" get pods -A
The token is written to stdout only and never logged. (`--format=exec-credential`
is deferred.)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L3kDaivS287GLUJSPkeY6h
Signed-off-by: Michael Hotan <mike@union.ai>
mhotan
force-pushed
the
mike/flyte-auth-token
branch
from
September 25, 2026 06:13
1f6fa9c to
189cb5c
Compare
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L3kDaivS287GLUJSPkeY6h Signed-off-by: Michael Hotan <mike@union.ai>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L3kDaivS287GLUJSPkeY6h Signed-off-by: Michael Hotan <mike@union.ai>
Signed-off-by: Michael Hotan <mike@union.ai>
Signed-off-by: Michael Hotan <mike@union.ai>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a
flyte authgroup with atokensubcommand that prints the CLI's current access token to stdout. It reuses the authenticator the rest of the CLI uses (endpoint, auth mode, TLS settings) and refreshes when the cached token is missing, expired or within 120s of expiry. If the token can't be parsed, it refreshes rather than print it.This lets tools pass a Flyte identity inline without writing credentials to disk, e.g. querying a Flyte-authorized endpoint with kubectl:
(
KUBECONFIG=/dev/nullstops kubectl from applying the current context's CA to that server.)The token goes to stdout only and is never logged.
--format=exec-credentialis left for a follow-up. Unit tests cover the expiry check and the command wiring.🤖 Generated with Claude Code
https://claude.ai/code/session_01L3kDaivS287GLUJSPkeY6h