Skip to content

Add per-identity-provider override for Supervisor session lifetime - #3287

Open
JHansen2000 wants to merge 2 commits into
vmware:mainfrom
JHansen2000:config-token-expiration
Open

JHansen2000 wants to merge 2 commits into
vmware:mainfrom
JHansen2000:config-token-expiration

Conversation

@JHansen2000

Copy link
Copy Markdown

Add per-identity-provider override for Supervisor session lifetime

Adds an optional sessionLifetimeSeconds field to FederationDomain.spec.identityProviders[], letting administrators override the Supervisor's default 9-hour refresh token lifetime on a per-identity-provider basis. This can be set shorter or longer than the default.

This does not change how or when the upstream identity provider expires its own tokens or session- the upstream IDP's expiration still governs independently, and can still end a Supervisor session earlier than this value if it expires first. This setting only adjusts how long the Supervisor's own refresh token may be used before the user must interactively reauthenticate.

Documentation has been updated to describe the new field and its interaction with the existing 9-hour default.

The codegen tooling was used to regenerate the Go API code and CRD manifests under generated/.

Fixes #1004

Testing

  • Linting: 18 issues, unchanged from main.
  • Unit tests: 39 failing, unchanged from main. New unit tests were added to cover this change.
  • Integration tests: 258/496 passing, vs. 213/496 on main. No new integration tests were added as part of this change.
  • Manual: Built and deployed the new image to a cluster. Verified the new configuration option behaves as expected with no unexpected side effects observed.

Release Note

Release note:

FederationDomain identity providers can now optionally override the Supervisor's default 9-hour session lifetime via `spec.identityProviders[].sessionLifetimeSeconds`. This only controls how long the Supervisor's own refresh token may be used; it does not change any expiration imposed by the upstream identity provider itself.

FederationDomain.spec.identityProviders[] now accepts an optional
sessionLifetimeSeconds, letting administrators extend the default
9-hour refresh token lifetime for a specific identity provider.
Addresses vmware#1004.

Signed-off-by: Jacob Hansen <2000.jihansen@gmail.com>
@netlify

netlify Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for pinniped-dev canceled.

Name Link
🔨 Latest commit 8d24105
🔍 Latest deploy log https://app.netlify.com/projects/pinniped-dev/deploys/6ab40fffbcd1fd0008d1b593

@legal-compliance-bot

Copy link
Copy Markdown

🛑 Legal Compliance Check Failed

Hi @JHansen2000, thank you for your contribution!

To merge this Pull Request, you must sign our DCO.

Note: Even if you signed off your commits locally (using git commit -s), you must post the comment below to register your signature with our automated system.
Note: This is a one-time process. Once signed, future contributions to this repository will be verified automatically.

1. Read the Document: Click here to read the DCO
2. Sign via Comment: Copy and paste the exact line below into a new comment on this Pull Request:

I have read the DCO Document and I hereby sign the DCO for this and all future contributions.

⏳ Processing Schedule:
Our 'Compliance Sweeper' runs automatically approximately every 15-20 minutes.
After you post the comment, your status will update automatically during the next scheduled run.
You do not need to take any further action.

Signed-off-by: Jacob Hansen <2000.jihansen@gmail.com>
@JHansen2000
JHansen2000 force-pushed the config-token-expiration branch from 17caf28 to 8d24105 Compare September 23, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pinniped Supervisor - interactively authenticate once per day/week/month

1 participant