Skip to content

Epic: Credential Management #810

Description

@shaneutt

Upstream credential injection and lifecycle management for multi-provider AI gateway deployments. Workloads never handle provider API keys or cloud credentials. The gateway strips client-supplied credentials and injects the correct provider-specific credential.

Scope

  • Per-cluster API key injection and client credential stripping (shipped via credential_injection filter)
  • AWS SigV4 per-request signing for Bedrock
  • Azure AD / Entra ID token exchange
  • GCP Workload Identity with OAuth2 token refresh
  • Automatic short-lived token rotation
  • Dynamic runtime credential injection
  • Credential redaction in observability

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions