mirror of
https://github.com/anthropics/claude-code-action.git
synced 2026-08-21 19:08:57 +08:00
fix: share one exchanged WIF credential across spawned Claude processes (#1407)
* fix: share one exchanged WIF credential across spawned Claude processes GitHub OIDC tokens are single-use at the Anthropic token-exchange endpoint (the same jti cannot be exchanged twice). With plugins configured, the action spawns several short-lived claude processes (plugin marketplace add, one plugin install per plugin, then the main query). Each resolved federation from bare env vars and exchanged the same identity-token file independently: the first exchange succeeded and every later process got 401 (jti_reused), which the main query retried for ~3 minutes before failing the job. The SDK only enables its on-disk credentials cache when federation is loaded from a profile config file, not from bare env vars. Write a profile pointing at the identity-token file and select it via ANTHROPIC_CONFIG_DIR / ANTHROPIC_PROFILE so the first process exchanges once and the rest reuse the cached access token. The env vars are kept as a fallback for CLIs that predate profile support. * fix: scope the WIF credential cache per federation config Address review feedback on the shared-credentials-cache fix: - Embed a fingerprint of the federation inputs (rule, org, service account, workspace, base URL, scope) in the config dir name. The SDK cache reuses a token on expires_at alone and RUNNER_TEMP is per-job, so a later step with different federation inputs would silently reuse the first step's token. service_account_id and scope are included beyond the reviewed list because both are sent in the exchange request body and change which credential is minted. - Skip the action-managed profile with a warning when the operator has already set ANTHROPIC_CONFIG_DIR or ANTHROPIC_PROFILE. - Shrink the profile to the minimal file-backed form; the CLI's bundled SDK gap-fills the federation fields from the env vars the action already exports (verified against the pinned 2.1.173 binary). - Remove the token dir in stop() so the identity token and the cached exchanged credential don't outlive the step. - Document that cache sharing relies on the plugin subprocesses spawning sequentially.
This commit is contained in:
@@ -75,7 +75,8 @@ async function run() {
|
||||
core.setOutput("conclusion", "failure");
|
||||
process.exit(1);
|
||||
} finally {
|
||||
// Stop refreshing the workload identity token file so the process can exit
|
||||
// Stop refreshing the workload identity token file (so the process can
|
||||
// exit) and delete the token material so it doesn't outlive this step
|
||||
workloadIdentity?.stop();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -15,7 +15,8 @@
|
||||
*/
|
||||
|
||||
import * as core from "@actions/core";
|
||||
import { mkdirSync, writeFileSync } from "fs";
|
||||
import { createHash } from "crypto";
|
||||
import { mkdirSync, rmSync, writeFileSync } from "fs";
|
||||
import { join } from "path";
|
||||
import { retryWithBackoff } from "./retry";
|
||||
|
||||
@@ -50,6 +51,63 @@ async function fetchIdentityToken(audience: string) {
|
||||
return retryWithBackoff(() => core.getIDToken(audience));
|
||||
}
|
||||
|
||||
/**
|
||||
* Writes a profile config that switches federation resolution to the
|
||||
* file-backed path. Resolving federation through a profile (rather than bare
|
||||
* env vars) enables the SDK's on-disk credentials cache, so the several
|
||||
* `claude` processes the action spawns (plugin installs, main query) share
|
||||
* one exchanged access token instead of each re-exchanging the single-use
|
||||
* GitHub OIDC token, which fails with 401 (`jti_reused`).
|
||||
*
|
||||
* The profile is intentionally minimal: the SDK gap-fills the federation
|
||||
* fields (rule, organization, identity-token file, service account, base URL)
|
||||
* from the ANTHROPIC_* env vars the action already exports, so the file only
|
||||
* needs to exist to turn the cache on.
|
||||
*
|
||||
* The config dir name embeds a fingerprint of the federation inputs. The
|
||||
* SDK's cache reuses a token on `expires_at` alone, with no record of the
|
||||
* config that minted it, and the token's scope is bound at mint time — so a
|
||||
* later action step in the same job (RUNNER_TEMP is per-job) with different
|
||||
* federation inputs must land in a different dir or it would silently reuse
|
||||
* the first step's token.
|
||||
*
|
||||
* Sharing the cache is only safe while the action spawns its `claude`
|
||||
* subprocesses sequentially: the SDK cache is not cross-process serialized,
|
||||
* and concurrent cache misses would each re-exchange the same single-use
|
||||
* identity token. Parallelizing the plugin installs would reintroduce the
|
||||
* `jti_reused` failures.
|
||||
*/
|
||||
function writeFederationProfile(baseDir: string): string {
|
||||
// Every input that changes which credential the exchange mints must be in
|
||||
// here; service_account_id and scope are sent in the exchange request body.
|
||||
const fingerprint = createHash("sha256")
|
||||
.update(
|
||||
JSON.stringify([
|
||||
process.env.ANTHROPIC_FEDERATION_RULE_ID?.trim() ?? "",
|
||||
process.env.ANTHROPIC_ORGANIZATION_ID?.trim() ?? "",
|
||||
process.env.ANTHROPIC_SERVICE_ACCOUNT_ID?.trim() ?? "",
|
||||
process.env.ANTHROPIC_WORKSPACE_ID?.trim() ?? "",
|
||||
process.env.ANTHROPIC_BASE_URL?.trim() ?? "",
|
||||
process.env.ANTHROPIC_SCOPE?.trim() ?? "",
|
||||
]),
|
||||
)
|
||||
.digest("hex")
|
||||
.slice(0, 16);
|
||||
const configDir = join(baseDir, `config-${fingerprint}`);
|
||||
|
||||
mkdirSync(join(configDir, "configs"), { recursive: true, mode: 0o700 });
|
||||
writeFileSync(
|
||||
join(configDir, "configs", "default.json"),
|
||||
JSON.stringify(
|
||||
{ version: "1.0", authentication: { type: "oidc_federation" } },
|
||||
null,
|
||||
2,
|
||||
),
|
||||
{ mode: 0o600 },
|
||||
);
|
||||
return configDir;
|
||||
}
|
||||
|
||||
/**
|
||||
* Fetches a GitHub Actions OIDC token, writes it to a file in RUNNER_TEMP,
|
||||
* exports ANTHROPIC_IDENTITY_TOKEN_FILE, and starts a background refresh so
|
||||
@@ -57,7 +115,8 @@ async function fetchIdentityToken(audience: string) {
|
||||
*
|
||||
* Returns undefined when federation is not configured or is shadowed by a
|
||||
* higher-precedence credential. Callers must invoke stop() when execution
|
||||
* finishes.
|
||||
* finishes; it also deletes the identity token and any cached exchanged
|
||||
* credential.
|
||||
*/
|
||||
export async function setupWorkloadIdentity(): Promise<
|
||||
WorkloadIdentityHandle | undefined
|
||||
@@ -101,6 +160,17 @@ export async function setupWorkloadIdentity(): Promise<
|
||||
}
|
||||
|
||||
process.env.ANTHROPIC_IDENTITY_TOKEN_FILE = tokenFile;
|
||||
if (
|
||||
process.env.ANTHROPIC_CONFIG_DIR?.trim() ||
|
||||
process.env.ANTHROPIC_PROFILE?.trim()
|
||||
) {
|
||||
core.warning(
|
||||
"ANTHROPIC_CONFIG_DIR or ANTHROPIC_PROFILE is already set, so the action will not write its own federation profile. Credential caching across the spawned Claude processes follows the existing profile configuration.",
|
||||
);
|
||||
} else {
|
||||
process.env.ANTHROPIC_CONFIG_DIR = writeFederationProfile(tokenDir);
|
||||
process.env.ANTHROPIC_PROFILE = "default";
|
||||
}
|
||||
console.log(
|
||||
`Workload identity federation configured (rule: ${process.env.ANTHROPIC_FEDERATION_RULE_ID}, identity token file: ${tokenFile})`,
|
||||
);
|
||||
@@ -115,6 +185,12 @@ export async function setupWorkloadIdentity(): Promise<
|
||||
|
||||
return {
|
||||
tokenFile,
|
||||
stop: () => clearInterval(refreshInterval),
|
||||
stop: () => {
|
||||
clearInterval(refreshInterval);
|
||||
// RUNNER_TEMP is per-job, not per-step: remove the identity token, the
|
||||
// profile, and the cached exchanged credential so they don't outlive
|
||||
// this step.
|
||||
rmSync(tokenDir, { recursive: true, force: true });
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user