Repository navigation
fix: repair token-broker build by bumping authlib past module rename - #538
Merged
Merged
Conversation
token-broker/go.mod pinned authlib to ce3417655ee8 (2026-06-18), which
predates the Kagenti -> Rossoctl rename. At that commit authlib's go.mod
still declares:
module github.com/kagenti/kagenti-extensions/authbridge/authlib
while token-broker requires github.com/rossoctl/cortex/authbridge/authlib.
Go rejects the path mismatch, so the module failed to build at all:
cmd/main.go:33:2: parsing go.mod:
module declares its path as: github.com/kagenti/kagenti-extensions/authbridge/authlib
but was required as: github.com/rossoctl/cortex/authbridge/authlib
Bump authlib to 2d373605612d (cortex v0.7.0-alpha.10), matching the
authbridge image tags already pinned in charts/operator/values.yaml.
go mod tidy carries the transitive updates and raises the go directive to
1.26.5, which authlib now requires.
There is no API drift: token-broker uses only validation.NewLazyJWKSVerifier
and validation.Verifier, and authlib's jwtvalidation/validation package is
byte-identical between the two commits. Build, vet, and all 8 test packages
pass after the bump.
Also add a test-token-broker CI job. The workflow-level
defaults.run.working-directory scopes every existing job to operator/, so
nothing compiled this separate module -- which is why a total build failure
shipped in v0.4.0-rc.1 unnoticed. The new job overrides that default and
runs build, vet, and tests.
Fixes #537
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Mariusz Sabath <mrsabath@gmail.com>
mrsabath
force-pushed
the
fix/token-broker-authlib-module-path
branch
from
September 17, 2026 21:56
6ea4a1e to
12ed1b4
Compare
davidhadas
approved these changes
Sep 18, 2026
davidhadas
left a comment
Contributor
There was a problem hiding this comment.
/lgtm
Problem: token-broker doesn't build on main. Its go.sum is missing the authlib hashes, and its go.mod pins a pre-rename cortex commit. No CI job compiles this module, so it shipped broken in v0.4.0-rc.1 and nobody noticed.
Fix: Bump the authlib pin to a post-rename commit, restore the go.sum hashes, and add a CI job that builds and tests the module.
Verified:
- The CI job overrides the workflow-level working-directory: operator, so it tests token-broker/ and not the wrong directory.
- The pin matches the authbridge images in values.yaml:247-249, so the broker and sidecar use the same library version.
- Transitive bumps are patch-level only — no k8s.io/*, no controller-runtime.
Non-blocking: go directive goes to 1.26.5 while operator/go.mod is lower — reconcile at the module merge (#536 item 2). And token-broker still has no lint job.
Approving. Closing #490, which fixed the same bug in July but pins an older commit and adds no CI.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
token-brokerdoes not build at all onmain. Itsauthlibdependency is pinned toce3417655ee8(2026-06-18), which predates the Kagenti → Rossoctl rename. At that commitauthlib/go.modstill declares the old module path, so Go rejects the requirement before compiling anything:Changes
Bump
authlibto2d373605612d(cortexv0.7.0-alpha.10) — chosen to match the authbridge image tags already pinned incharts/operator/values.yaml, rather than introducing a version skew.go mod tidycarries the transitive updates and raises thegodirective to 1.26.5, which current authlib requires.Add a
test-token-brokerCI job. The workflow-leveldefaults.run.working-directory: operatorscopes every existing job to the operator module, so nothing in CI ever compiledtoken-broker/. That is why a total build failure shipped inv0.4.0-rc.1unnoticed. The new job overrides that default and runs build, vet, and tests.Verification
go build ./...— passesgo vet ./...— passesgo test ./...— passes, all 8 packages (cmd,internal/api,internal/auth,internal/cache,internal/core,internal/oauth,internal/session,pkg/oauth)-mod=readonly, confirming the committedgo.mod/go.sumare complete and CI needs no tidy stepNo API drift.
token-brokeruses exactly two authlib symbols —validation.NewLazyJWKSVerifierandvalidation.Verifier— andauthbridge/authlib/plugins/jwtvalidation/validation/is byte-identical between the old and new commits. This was purely a module-path problem.Notes
I checked whether the stale rename appears elsewhere: all
go.mod/go.sumfiles across operator, rossoctl, and cortex, plusghcr.io/kagentiimage references.token-brokeris the only affected module — the rename was otherwise thorough. It survived precisely because nothing built it.Related to #536 (folding
bundle-serviceandtoken-brokerinto the operator image). If that lands,token-broker/go.moddisappears in the module merge and this pin goes with it — but the CI job and the fix stand on their own until then, and the module should not be left unbuildable in the meantime.Fixes #537
🤖 Generated with Claude Code