Skip to main content

OIDC and mTLS token exchange

OIDC (JWT bearer)​

Set both keys:

[auth]
require = true
oidc_issuer = "https://idp.example.com"
oidc_audience = "fluxvm"

FluxVM discovers {issuer}/.well-known/openid-configuration, fetches JWKS, and validates iss, aud, exp, and signature (kid). Claims:

ClaimUse
fluxvm_role or roleadmin / read-only (default read-only)
fluxvm_tenant / tenant / orgstamped tenant
preferred_username / email / subaudit actor

Static [[auth.tokens]] still work and are checked first.

mTLS​

[tls]
cert = "/etc/fluxvm/tls/server.crt"
key = "/etc/fluxvm/tls/server.key"
client_ca = "/etc/fluxvm/tls/client-ca.crt"

fluxctl serve uses rustls with WebPkiClientVerifier. After the handshake, identity can also be passed as headers (for a trusted frontend):

  • X-Client-Cert-CN — actor
  • X-Client-Cert-Role — admin or omitted (read-only)
  • X-Client-Cert-Tenant — tenant

Headers are honored only when tls.client_ca is configured (mTLS on). Do not put FluxVM behind a proxy that blindly injects these headers without verifying the client certificate.