René's URL Explorer Experiment


Title: Feast Operator ignores OIDC secretRef - accepts syntax but doesn't inject secret values · Issue #5676 · feast-dev/feast · GitHub

Open Graph Title: Feast Operator ignores OIDC secretRef - accepts syntax but doesn't inject secret values · Issue #5676 · feast-dev/feast

X Title: Feast Operator ignores OIDC secretRef - accepts syntax but doesn't inject secret values · Issue #5676 · feast-dev/feast

Description: Expected Behavior When a FeatureStore specifies spec.authz.oidc.secretRef, the operator should: 1.Read the referenced Kubernetes secret containing OIDC credentials 2.Inject secret values (client_secret, username, password) into container...

Open Graph Description: Expected Behavior When a FeatureStore specifies spec.authz.oidc.secretRef, the operator should: 1.Read the referenced Kubernetes secret containing OIDC credentials 2.Inject secret values (client_se...

X Description: Expected Behavior When a FeatureStore specifies spec.authz.oidc.secretRef, the operator should: 1.Read the referenced Kubernetes secret containing OIDC credentials 2.Inject secret values (client_se...

Opengraph URL: https://github.com/feast-dev/feast/issues/5676

X: @github

direct link

Domain: github.com


Hey, it has json ld scripts:
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Feast Operator ignores OIDC secretRef - accepts syntax but doesn't inject secret values","articleBody":"## Expected Behavior \nWhen a FeatureStore specifies spec.authz.oidc.secretRef, the operator should:\n1.Read the referenced Kubernetes secret containing OIDC credentials\n2.Inject secret values (client_secret, username, password) into container environments\n3.Generate complete OIDC configuration enabling full authentication for both API and UI\n4.Redirect UI access through OIDC provider (Keycloak) login flow\n\n## Current Behavior\nThe operator:\n1.Accepts secretRef configuration without validation errors\n2.Completely ignores the referenced secret - no mounting or injection occurs\n3.Generates incomplete OIDC config with only basic fields (auth_discovery_url, client_id)\n4.Results in broken authentication:\na.API shows AuthManagerType.OIDC but authentication fails due to missing client_secret\nb.UI serves directly without any authentication redirect\n\n## Steps to reproduce\n1.Create OIDC Secret\n```yaml\napiVersion: v1\nkind: Secret\nmetadata:\n  name: oidc-secret\n  namespace: feast\nstringData:\n  client_id: your-client-id\n  client_secret: your-client-secret  \n  auth_discovery_url: https://your-keycloak/realms/realm/.well-known/openid_configuration\n  username: your-username\n  password: your-password\n```\n\n2. Create FeatureStore with secretRef:\n```yaml\napiVersion: feast.dev/v1alpha1\nkind: FeatureStore\nmetadata:\n  name: sample-oidc-auth\nspec:\n  feastProject: my_project\n  authz:\n    oidc:\n      secretRef:\n        name: oidc-secret\n  services:\n    ui: {}\n```\n3.Verify the bug:\nContainer shows OIDC type but incomplete config\n```bash\nkubectl logs deployment/feast-sample-oidc-auth -c online\n```\nOUTPUT: INFO:fastapi:Auth type: AuthManagerType.OIDC\n\n\u003cimg width=\"1498\" height=\"343\" alt=\"Image\" src=\"https://github.com/user-attachments/assets/db4df218-6723-46c9-b6c5-62edc6fee7f1\" /\u003e\n\nNo secret values injected as environment variables\n```bash\nkubectl exec deployment/feast-sample-oidc-auth -c ui -- env | grep client_\n```\nOUTPUT: (empty)\n\n\u003cimg width=\"1498\" height=\"272\" alt=\"Image\" src=\"https://github.com/user-attachments/assets/34804818-36fb-404c-8e78-12c3aa8da454\" /\u003e\n\nCheck generated config - missing client_secret\n```bash\nkubectl exec deployment/feast-sample-oidc-auth -c ui -- env | grep TMP_FEATURE_STORE_YAML_BASE64\n```\nDecode shows: only auth_discovery_url and client_id, missing client_secret\nexample:\n```yaml\n$ echo \"\u003cbase64-string\u003e\" | base64 --decode\nproject: my_project\nprovider: local\nonline_store:\n    path: /feast-data/online_store.db\n    type: sqlite\nregistry:\n    path: /feast-data/registry.db\n    registry_type: file\nauth:\n    type: oidc\n    auth_discovery_url: https://example.com/keycloak/realms/myrealm/.well-known/openid_configuration\n    client_id: my-client-id\nentity_key_serialization_version: 3\n```\nNotice: Missing client_secret, username, password from secret!\n\nHence,UI accessible without authentication redirect\nReturns HTML directly instead of OIDC redirect\n\n### Specifications\n\nVersion: Feast operator with feature-server:0.54.0\nPlatform: Kubernetes\nSubsystem: feast-operator (FeatureStore CRD controller)\n\n## Possible Solution\nThe operator needs to implement secret processing in the FeatureStore controller:\n1.Read secret values when spec.authz.oidc.secretRef is specified\n2.Mount secret as volume or inject as environment variables into containers\n3.Modify feature_store.yaml generation to include complete OIDC configuration with secret values\n4.Ensure both online and ui containers receive the OIDC credentials for proper authentication","author":{"url":"https://github.com/RSBhoomika","@type":"Person","name":"RSBhoomika"},"datePublished":"2025-10-17T10:01:00.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":2},"url":"https://github.com/5676/feast/issues/5676"}

route-pattern/_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format)
route-controllervoltron_issues_fragments
route-actionissue_layout
fetch-noncev2:ed624fb8-a63e-727b-b166-ebfc9b3aae1c
current-catalog-service-hash81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114
request-id833C:338AF6:88E354E:B41541F:696DE603
html-safe-nonce56d524665f39345ccbb0abbd432477d03ac93149915cc90afcfd60bdf8ab95ec
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI4MzNDOjMzOEFGNjo4OEUzNTRFOkI0MTU0MUY6Njk2REU2MDMiLCJ2aXNpdG9yX2lkIjoiMjY3NTMwOTIzMTc5NDQxNTEwOCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9
visitor-hmac3b1fe4a1d59fe0414628b6799a019ccc759abc375bc37b905e8c91a6bdaca4ff
hovercard-subject-tagissue:3525347867
github-keyboard-shortcutsrepository,issues,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///voltron/issues_fragments/issue_layout
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/feast-dev/feast/5676/issue_layout
twitter:imagehttps://opengraph.githubassets.com/ae6e45f60a8304675df774164ee64d2dc9890a1667501d68edf956ba95f0af27/feast-dev/feast/issues/5676
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/ae6e45f60a8304675df774164ee64d2dc9890a1667501d68edf956ba95f0af27/feast-dev/feast/issues/5676
og:image:altExpected Behavior When a FeatureStore specifies spec.authz.oidc.secretRef, the operator should: 1.Read the referenced Kubernetes secret containing OIDC credentials 2.Inject secret values (client_se...
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
og:author:usernameRSBhoomika
hostnamegithub.com
expected-hostnamegithub.com
None4922b452d03cd8dbce479d866a11bc25b59ef6ee2da23aa9b0ddefa6bd4d0064
turbo-cache-controlno-preview
go-importgithub.com/feast-dev/feast git https://github.com/feast-dev/feast.git
octolytics-dimension-user_id57027613
octolytics-dimension-user_loginfeast-dev
octolytics-dimension-repository_id161133770
octolytics-dimension-repository_nwofeast-dev/feast
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id161133770
octolytics-dimension-repository_network_root_nwofeast-dev/feast
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release7e5ae23c70136152637ceee8d6faceb35596ec46
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/feast-dev/feast/issues/5676#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Ffeast-dev%2Ffeast%2Fissues%2F5676
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Ffeast-dev%2Ffeast%2Fissues%2F5676
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fissues_fragments%2Fissue_layout&source=header-repo&source_repo=feast-dev%2Ffeast
Reloadhttps://github.com/feast-dev/feast/issues/5676
Reloadhttps://github.com/feast-dev/feast/issues/5676
Reloadhttps://github.com/feast-dev/feast/issues/5676
feast-dev https://github.com/feast-dev
feasthttps://github.com/feast-dev/feast
Notifications https://github.com/login?return_to=%2Ffeast-dev%2Ffeast
Fork 1.2k https://github.com/login?return_to=%2Ffeast-dev%2Ffeast
Star 6.6k https://github.com/login?return_to=%2Ffeast-dev%2Ffeast
Code https://github.com/feast-dev/feast
Issues 176 https://github.com/feast-dev/feast/issues
Pull requests 58 https://github.com/feast-dev/feast/pulls
Discussions https://github.com/feast-dev/feast/discussions
Actions https://github.com/feast-dev/feast/actions
Security Uh oh! There was an error while loading. Please reload this page. https://github.com/feast-dev/feast/security
Please reload this pagehttps://github.com/feast-dev/feast/issues/5676
Insights https://github.com/feast-dev/feast/pulse
Code https://github.com/feast-dev/feast
Issues https://github.com/feast-dev/feast/issues
Pull requests https://github.com/feast-dev/feast/pulls
Discussions https://github.com/feast-dev/feast/discussions
Actions https://github.com/feast-dev/feast/actions
Security https://github.com/feast-dev/feast/security
Insights https://github.com/feast-dev/feast/pulse
New issuehttps://github.com/login?return_to=https://github.com/feast-dev/feast/issues/5676
New issuehttps://github.com/login?return_to=https://github.com/feast-dev/feast/issues/5676
Feast Operator ignores OIDC secretRef - accepts syntax but doesn't inject secret valueshttps://github.com/feast-dev/feast/issues/5676#top
kind/bughttps://github.com/feast-dev/feast/issues?q=state%3Aopen%20label%3A%22kind%2Fbug%22
priority/p2https://github.com/feast-dev/feast/issues?q=state%3Aopen%20label%3A%22priority%2Fp2%22
https://github.com/RSBhoomika
https://github.com/RSBhoomika
RSBhoomikahttps://github.com/RSBhoomika
on Oct 17, 2025https://github.com/feast-dev/feast/issues/5676#issue-3525347867
https://private-user-images.githubusercontent.com/72779921/502517754-db4df218-6723-46c9-b6c5-62edc6fee7f1.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Njg4MTAyODgsIm5iZiI6MTc2ODgwOTk4OCwicGF0aCI6Ii83Mjc3OTkyMS81MDI1MTc3NTQtZGI0ZGYyMTgtNjcyMy00NmM5LWI2YzUtNjJlZGM2ZmVlN2YxLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjAxMTklMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwMTE5VDA4MDYyOFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWM1ZjU0ZDYyNDU4OTlhODI1ZmE1NDBlNjI1NTg3ZmU2ZmI5MTBmMzFiNjY5YTAxMzE1NzM0YmVhMjcyNDQzNzkmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.2a941boeq9i4AMYMpBxz7OeaJz7Q4x67YO8dIZz191Q
https://private-user-images.githubusercontent.com/72779921/502517584-34804818-36fb-404c-8e78-12c3aa8da454.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Njg4MTAyODgsIm5iZiI6MTc2ODgwOTk4OCwicGF0aCI6Ii83Mjc3OTkyMS81MDI1MTc1ODQtMzQ4MDQ4MTgtMzZmYi00MDRjLThlNzgtMTJjM2FhOGRhNDU0LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjAxMTklMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwMTE5VDA4MDYyOFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTFlZTJhZTM1YWZkMjg0ODVmZjc5MjY5NmNiZjhkYzgzYmRkYzhjMjIwNDQ1ZTVmOTgyM2YxZTNhMzc5NWEyZmYmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.-2UiRlnI2iqXsintJ6LtH2gdsI1DOBkmkScJKArYmqw
kind/bughttps://github.com/feast-dev/feast/issues?q=state%3Aopen%20label%3A%22kind%2Fbug%22
priority/p2https://github.com/feast-dev/feast/issues?q=state%3Aopen%20label%3A%22priority%2Fp2%22
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.