Skip to content

docs: document environment agent authentication (inbound + outbound) - #23

Draft
gabriel-farache wants to merge 1 commit into
dcm-project:mainfrom
gabriel-farache:docs/agent_auth
Draft

gabriel-farache wants to merge 1 commit into
dcm-project:mainfrom
gabriel-farache:docs/agent_auth

Conversation

@gabriel-farache

@gabriel-farache gabriel-farache commented Sep 21, 2026 •

Copy link
Copy Markdown

Adds a dedicated Environment Agent Authentication guide covering the two independent auth surfaces introduced by environment-agent#35 and environment-agent#38:

  • Inbound: AGENT_AUTH_DISABLED / AGENT_AUTH_ISSUER_URL / AGENT_AUTH_JWT_AUDIENCE protecting the agent's own REST API (external SP registration, provider listing), health-path bypass, RFC 7807 error format, and the intentional audience fail-open behavior.
  • Outbound: DCM_AUTH_TOKEN / DCM_AUTH_TOKEN_ENDPOINT / DCM_AUTH_CLIENT_ID / DCM_AUTH_CLIENT_SECRET for the agent's own registration/heartbeat calls to the control plane, mode precedence, token refresh and failure behavior, Keycloak service-account setup, and the known reference-realm audience-mapper gap.

Addresses the open documentation request from
environment-agent#35 (review thread on internal/config/config.go, dcm-project/environment-agent#35 (comment)): 'put agent auth enablement on the website... same idea as the CP guide.'

Content validated against the latest reviewed commits on both PR branches (config.go, jwt.go, middleware.go, token.go, client.go, main.go, openapi.yaml, README.md, decisions.md) rather than assumed from the PR descriptions alone.

Updates the control-plane Authentication guide's Service-providers callout and troubleshooting row to link to the new page instead of a vague 'still landing' note, and cross-links from Local Setup and the Getting Started index.

Summary by Sourcery

Document environment-agent authentication for protecting its API and authenticating calls to the control plane.

New Features:

  • Add a dedicated guide covering independent inbound and outbound authentication for the environment agent, including configuration, token handling, Keycloak setup, and troubleshooting.

Enhancements:

  • Clarify that environment-agent authentication is separate from control-plane authentication and update related setup and troubleshooting guidance.

Documentation:

  • Link the new environment-agent authentication guide from the Getting Started index, control-plane Authentication guide, and Local Setup documentation.

Adds a dedicated Environment Agent Authentication guide covering the
two independent auth surfaces introduced by environment-agent#35 and
environment-agent#38:

- Inbound: AGENT_AUTH_DISABLED / AGENT_AUTH_ISSUER_URL /
  AGENT_AUTH_JWT_AUDIENCE protecting the agent's own REST API (external
  SP registration, provider listing), health-path bypass, RFC 7807
  error format, and the intentional audience fail-open behavior.
- Outbound: DCM_AUTH_TOKEN / DCM_AUTH_TOKEN_ENDPOINT /
  DCM_AUTH_CLIENT_ID / DCM_AUTH_CLIENT_SECRET for the agent's own
  registration/heartbeat calls to the control plane, mode precedence,
  token refresh and failure behavior, Keycloak service-account setup,
  and the known reference-realm audience-mapper gap.

Addresses the open documentation request from
environment-agent#35 (review thread on internal/config/config.go,
dcm-project/environment-agent#35 (comment)):
'put agent auth enablement on the website... same idea as the CP
guide.'

Content validated against the latest reviewed commits on both PR
branches (config.go, jwt.go, middleware.go, token.go, client.go,
main.go, openapi.yaml, README.md, decisions.md) rather than assumed
from the PR descriptions alone.

Updates the control-plane Authentication guide's Service-providers
callout and troubleshooting row to link to the new page instead of a
vague 'still landing' note, and cross-links from Local Setup and the
Getting Started index.

Signed-off-by: Gabriel Farache <gfarache@redhat.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Signed-off-by: gabriel-farache <gfarache@redhat.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant