Update build configuration and improve token handling
Build and Test / verify (push) Failing after 1m22s

- Change CI container image to debian:trixie-slim and set GOPROXY.
- Update Go version to 1.26 in Dockerfile and go.mod.
- Refactor token validation to use SHA-256 hashes instead of plain tokens.
- Add network policy to restrict access to the service.
- Enhance README with new configuration details and usage examples.
- Add tests for new token hash validation logic.
This commit is contained in:
2026-07-11 22:08:56 +02:00
parent ea4aac6641
commit 1acdbb5519
8 changed files with 195 additions and 57 deletions
+3 -1
View File
@@ -4,6 +4,8 @@ metadata:
name: gitea-mcp-auth-proxy
labels:
app: gitea-mcp-auth-proxy
annotations:
security.note/healthz: "Do not expose /healthz publicly; keep service internal and restrict ingress at network/ingress layer."
spec:
replicas: 1
selector:
@@ -24,7 +26,7 @@ spec:
env:
- name: AUTH_PROXY_LISTEN_ADDR
value: ":8080"
- name: AUTH_PROXY_TOKENS_DIR
- name: AUTH_PROXY_TOKEN_HASHES_DIR
value: /var/run/secrets/auth-proxy
- name: AUTH_PROXY_LOG_LEVEL
value: info