feat: add custom auth header support in edge mode - #79
Open
TMHBOFH wants to merge 1 commit into
Open
Conversation
Signed-off-by: TMHBOFH <itsystem.bofh@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds custom authentication header support for Edge Mode to allow connections through external authentication proxies (like Traefik with ForwardAuth, Authentik, or Cloudflare Access).
Previously, the Hawser agent could not pass extra HTTP headers when establishing the WebSocket connection to the Dockhand server. If the server was protected by an authentication layer, the connection was rejected and failed with:
WebSocket dial failed: websocket: bad handshakeChanges
internal/config/config.go: Added CUSTOM_AUTH_HEADER and CUSTOM_AUTH_TOKEN environment variables to the configuration.internal/edge/client.go: Updated the WebSocket dialer to check for the custom auth variables and inject them into the HTTP request headers during the handshake. Added[INFO] Using custom authentication header: ...logging.README.md: Added documentation and usage examples for the new environment variables.Usage
docker-compose.yml:
docker run:
-e CUSTOM_AUTH_HEADER=Authorization -e CUSTOM_AUTH_TOKEN="Bearer <token>"Where the token is used to authenticate the Hawser agent against the external authentication layer in front of the Dockhand server.