feat(weave): federated identity support for weave - #7726
Draft
RyanBuccellato wants to merge 8 commits into
Draft
Conversation
Contributor
|
CLA Assistant Lite bot All contributors have signed the CLA ✍️ ✅ |
Codecov Report❌ Patch coverage is 📢 Thoughts on this report? Let us know! |
Author
|
I have read the CLA Document and I hereby sign the CLA |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds support for federated identity to weave. We currently support this in the standard wandb SDK, sort of reimplementing it for the weave SDK since they dont really share code today.
The way federated identity works is the user provides a JWT, we send that to gorilla to exchange for a Bearer token. This token is saved in a CREDENTIALS_FILE like the standard wandb SDK. This token will then get fed into the weave backend, which then forwards it to gorilla (which already knows how this credential works). The token will eventually expire and then the SDK will need to exchange it out for a new one.
Testing
Have a local script that went thru all the weave endpoints to test that they authed properly with federated identity. The one exception is inference (since local testing for that is a bit more involved) but inference requires a separate backend change to support anyways.