Skip to main content
Version: v3.9.0

Auth

The auth package centralizes cryptography and JWT lifecycle for Edgelet: agent signing keys, Controller JWTs, EdgeletAPI tokens, service account minting, Edge Guard signatures, TLS material for EdgeletAPI, and bootstrap vs provisioned validation policy.

Code: internal/auth/

Purpose​

  • Generate and validate Ed25519-signed JWTs for Controller REST and EdgeletAPI
  • Reconcile /etc/edgelet/edgelet-api token file with agent provisioning state
  • Issue bootstrap unsigned JWTs when unprovisioned
  • Provide PKI paths and TLS config for EdgeletAPI server
  • Stable hash extraction for Edge Guard attestation comparison

Dependencies​

Depends onReason
storeHydrate agent private key from agent_credentials
configProvisioning state (iofogUuid, in-memory private key)
FilesystemToken file, cert/key paths under /etc/edgelet/
Used byReason
edgeletapiValidateEdgeletAPIJWT, middleware
fieldagentController JWT, token rotation workers
serviceaccountMint projected workload tokens
edgeguardSign attestation JWTs
cmd/edgelet bootstrapPKI generation on first start

JWT token uses​

tokenUse claimAudienceConsumer
controllerController URLField Agent → /api/v3/...
edgeletapiedgelet://edgeletapi/v1CLI, EdgeletAPI middleware
serviceaccountEdgelet bridge DNSWorkload pods (projected mount)
edgeguardedgelet://edgeguard/v1Attestation baseline in SQLite

Issuer constant: https://edgelet.default.svc.bridge.local.

EdgeletAPI validation policy​

ValidateEdgeletAPIJWT() in edgeletapi_jwt.go:

StateAccepted tokens
UnprovisionedUnsigned (alg: none) bootstrap JWT only; tokenUse must be edgeletapi
ProvisionedSigned Ed25519 only; validated via JWTManager.ValidateJWT() + claim checks

Required temporal claims on all tokens: iat, nbf, exp, jti.

Token file lifecycle​

EnsureEdgeletAPITokenForCurrentState() (edgeletapi_token_lifecycle.go):

  • Unprovisioned: write short-TTL bootstrap JWT (sub: system:edgeletadmin:bootstrap) with wildcard RBAC rules
  • Provisioned: signed admin JWT with edgelet.iofog.org rules *:*

Called on provision, deprovision, config reload, and from Field Agent rotation worker.

Token persistence: edgeletapi_token_file.go → /etc/edgelet/edgelet-api (mode 0600).

Agent private key​

  • Generated at provision; stored in SQLite agent_credentials (singleton row)
  • Hydrated into config + JWTManager at Field Agent start and on reload
  • Missing key blocks Controller auth paths and Edge Guard

PKI and TLS​

edgeletapi_pki.go, certificates.go, tls_config.go:

  • EdgeletAPI server cert/key and CA for CLI trust
  • Paths documented in Architecture persistence table

Configuration​

Auth reads provisioning state from config + DB, not standalone YAML keys except indirectly via provision flow.

ArtifactPath
CLI bearer token/etc/edgelet/edgelet-api
Client CA/etc/edgelet/edgeletapi-ca.crt
Server TLS/etc/edgelet/edgeletapi-*.crt/key

External APIs​

No HTTP server in this package. Surfaces through:

  • EdgeletAPI middleware (validation)
  • Field Agent Controller client (outbound signed JWT)
  • Service account projection files (token, ca.crt, edgelet.jwk)

Observability​

  • Log module name: "JWT Manager", "Edgelet API JWT"
  • Failed validation returns generic 401 at middleware (no claim leakage)

Failure modes​

SymptomTypical cause
CLI 401 after provisionStale bootstrap token; run token reconcile or re-read edgelet-api file
Controller auth failuresPrivate key not hydrated from DB
Edge Guard won't startUnprovisioned agent with frequency > 0 (forced to 0)

Code map​

FileRole
jwt.goJWTManager, Controller/SA/EdgeGuard token generation
edgeletapi_jwt.goEdgeletAPI validate + claim policy
edgeletapi_token_lifecycle.goBootstrap/signed reconcile
edgeletapi_token_file.goRead/write token file
edgeletapi_pki.goPKI bootstrap
crypto.goEd25519 helpers
certificates.go, tls_config.goTLS for EdgeletAPI

Related: Edgelet API module, Service account, EdgeGuard, Edgelet API.

Group 3See anything wrong with the document? Help us improve it!