Skip to content

fix: repair token-broker build by bumping authlib past module rename - #538

Merged
davidhadas merged 1 commit into
mainfrom
fix/token-broker-authlib-module-path
Sep 18, 2026
Merged

davidhadas merged 1 commit into
mainfrom
fix/token-broker-authlib-module-path

Conversation

@mrsabath

Copy link
Copy Markdown
Member

Summary

token-broker does not build at all on main. Its authlib dependency is pinned to ce3417655ee8 (2026-06-18), which predates the Kagenti → Rossoctl rename. At that commit authlib/go.mod still declares the old module path, so Go rejects the requirement before compiling anything:

cmd/main.go:33:2: github.com/rossoctl/cortex/authbridge/authlib@v0.0.0-20260619001334-ce3417655ee8: parsing go.mod:
	module declares its path as: github.com/kagenti/kagenti-extensions/authbridge/authlib
	        but was required as: github.com/rossoctl/cortex/authbridge/authlib

Changes

Bump authlib to 2d373605612d (cortex v0.7.0-alpha.10) — chosen to match the authbridge image tags already pinned in charts/operator/values.yaml, rather than introducing a version skew. go mod tidy carries the transitive updates and raises the go directive to 1.26.5, which current authlib requires.

Add a test-token-broker CI job. The workflow-level defaults.run.working-directory: operator scopes every existing job to the operator module, so nothing in CI ever compiled token-broker/. That is why a total build failure shipped in v0.4.0-rc.1 unnoticed. The new job overrides that default and runs build, vet, and tests.

Verification

  • go build ./... — passes
  • go vet ./... — passes
  • go test ./... — passes, all 8 packages (cmd, internal/api, internal/auth, internal/cache, internal/core, internal/oauth, internal/session, pkg/oauth)
  • Re-verified under -mod=readonly, confirming the committed go.mod/go.sum are complete and CI needs no tidy step

No API drift. token-broker uses exactly two authlib symbols — validation.NewLazyJWKSVerifier and validation.Verifier — and authbridge/authlib/plugins/jwtvalidation/validation/ is byte-identical between the old and new commits. This was purely a module-path problem.

Notes

I checked whether the stale rename appears elsewhere: all go.mod/go.sum files across operator, rossoctl, and cortex, plus ghcr.io/kagenti image references. token-broker is the only affected module — the rename was otherwise thorough. It survived precisely because nothing built it.

Related to #536 (folding bundle-service and token-broker into the operator image). If that lands, token-broker/go.mod disappears in the module merge and this pin goes with it — but the CI job and the fix stand on their own until then, and the module should not be left unbuildable in the meantime.

Fixes #537

🤖 Generated with Claude Code

@mrsabath
mrsabath requested review from a team as code owners September 17, 2026 21:30
token-broker/go.mod pinned authlib to ce3417655ee8 (2026-06-18), which
predates the Kagenti -> Rossoctl rename. At that commit authlib's go.mod
still declares:

    module github.com/kagenti/kagenti-extensions/authbridge/authlib

while token-broker requires github.com/rossoctl/cortex/authbridge/authlib.
Go rejects the path mismatch, so the module failed to build at all:

    cmd/main.go:33:2: parsing go.mod:
        module declares its path as: github.com/kagenti/kagenti-extensions/authbridge/authlib
                but was required as: github.com/rossoctl/cortex/authbridge/authlib

Bump authlib to 2d373605612d (cortex v0.7.0-alpha.10), matching the
authbridge image tags already pinned in charts/operator/values.yaml.
go mod tidy carries the transitive updates and raises the go directive to
1.26.5, which authlib now requires.

There is no API drift: token-broker uses only validation.NewLazyJWKSVerifier
and validation.Verifier, and authlib's jwtvalidation/validation package is
byte-identical between the two commits. Build, vet, and all 8 test packages
pass after the bump.

Also add a test-token-broker CI job. The workflow-level
defaults.run.working-directory scopes every existing job to operator/, so
nothing compiled this separate module -- which is why a total build failure
shipped in v0.4.0-rc.1 unnoticed. The new job overrides that default and
runs build, vet, and tests.

Fixes #537

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Mariusz Sabath <mrsabath@gmail.com>
@mrsabath
mrsabath force-pushed the fix/token-broker-authlib-module-path branch from 6ea4a1e to 12ed1b4 Compare September 17, 2026 21:56

@davidhadas davidhadas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

Problem: token-broker doesn't build on main. Its go.sum is missing the authlib hashes, and its go.mod pins a pre-rename cortex commit. No CI job compiles this module, so it shipped broken in v0.4.0-rc.1 and nobody noticed.

Fix: Bump the authlib pin to a post-rename commit, restore the go.sum hashes, and add a CI job that builds and tests the module.

Verified:

  • The CI job overrides the workflow-level working-directory: operator, so it tests token-broker/ and not the wrong directory.
  • The pin matches the authbridge images in values.yaml:247-249, so the broker and sidecar use the same library version.
  • Transitive bumps are patch-level only — no k8s.io/*, no controller-runtime.

Non-blocking: go directive goes to 1.26.5 while operator/go.mod is lower — reconcile at the module merge (#536 item 2). And token-broker still has no lint job.

Approving. Closing #490, which fixed the same bug in July but pins an older commit and adds no CI.

@davidhadas
davidhadas merged commit 1af3873 into main Sep 18, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

token-broker module fails to build: authlib pinned to pre-rename commit with old module path

3 participants