Skip to content

fix(providers): bind multi-route grants to admitted endpoints - #4152

Draft
shiju-nv wants to merge 1 commit into
NVIDIA:mainfrom
shiju-nv:fix/3657-admitted-endpoint/shiju-nv
Draft

shiju-nv wants to merge 1 commit into
NVIDIA:mainfrom
shiju-nv:fix/3657-admitted-endpoint/shiju-nv

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

Summary

Requests to different provider paths on one host now acquire the grant belonging to an endpoint that admitted that request. The relay checks each request on a persistent connection against current provider state, and rejects a grant if policy or provider installation changes before forwarding. This adds the missing multi-route hook and applies the same ownership checks to existing single-route REST injection.

Related Issue

Closes #3657

The implementation covers #3657's multi-route injection, isolation, persistent connections, failure recovery and refresh/expiry requirements. Native single-route MCP/JSON-RPC remains tracked separately in #3658, as #3657 permits. Native single-route GraphQL also still lacks its injection hook; this PR does not claim to add it. The broader issuer-expiry/TTL correction remains separate.

Changes

  • Generate endpoint owner IDs from provider identity and complete policy rules, carry them through policy and credential delivery, and ignore authored owner stamps. Global policies retain their existing replacement semantics.
  • Query which individual endpoints admit the request and caller, then filter credentials by those owners before selector ranking. Preserve ordinary union allows and global denies. Audit forwarding cannot borrow a grant from a denying owner.
  • Resolve from a fresh provider snapshot on each inspected request. Include installation identity in cache keys and check policy/provider freshness across acquisition and body buffering, including same-revision repair and HTTP/1.0 requests without Host.
  • Add gateway, OPA, relay, cache and Podman regressions. Document credential selection and refresh behavior in the provider-profile guide.

Testing

  • Checks appropriate to the affected code and behavior pass
  • Unit tests added/updated (if applicable)
  • E2E tests added/updated (if applicable)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

Carry gateway-derived endpoint owners through policy and credential delivery. Select grants only from owners that admit the current request, refresh provider snapshots per request, and reject superseded installations before forwarding.

Cover persistent routes, overlapping owners, denial, refresh, cache expiry and recovery with focused tests and a Podman regression.

Signed-off-by: Shiju <shiju@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

RFE: support dynamic credential injection for multiple provider paths on the same hostname

1 participant