Epic: BYOIDC bearer-token authentication for `confluent_sql`
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Quiet
- Tech stack
- python
- Domain
- api, authentication
Research direction
No files, tests, or entry points are named in the issue. Start by identifying the independently shippable children for the Flink data plane, then verify the stated authorization boundary against the Cloud OpenAPI specification. Done means covering the static external token and refreshing client-credentials modes while failing closed for control-plane requests.
Written by the indexing model from the issue text.
Description
Confluent Cloud customers who run their own OAuth/OIDC identity provider need to authenticate this driver with a bearer token they mint themselves — an external token, in Confluent's authorization vocabulary — rather than a Confluent API key + secret. This epic covers that BYOIDC (bring-your-own-IdP) surface end to end, as small independently-shippable children.
Scope boundary: Flink data plane only
By Confluent's authorization model (verified against the Cloud OpenAPI spec's per-operation AUTHORIZATIONS blocks), a raw external token authenticates the Flink data plane and nothing on api.confluent.cloud. None of /tableflow/v1, /connect/v1, /cmk/v2/clusters, or /org/v2/organizations accept external-access-token. So every child here is Flink-only, and the control plane fails closed with an error. Reaching the control plane with a caller identity is a different problem, covered in a separate epic, which mints Confluent's own tokens.
The bar: cover plugin #399's BYOIDC half
The neighboring Java Table API client shipped two BYOIDC-flavoured modes in one large PR: a static external-access-token and a refreshing client-credentials provider. This epic covers the same ground as a sequence of bounded children rather than one mega-PR
- Dominant language
- Python
- Stars
- 6
- Forks
- 1
- Avg merge
- 14h 58m
- Merged PRs (30d)
- 22
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from confluentinc/confluent-sql
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
confluentinc/confluent-sql#226 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
confluentinc/confluent-sql#224 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
confluentinc/confluent-sql#223 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
confluentinc/confluent-sql#125 ·
Maintainers usually reply within 1 day
-
List connectorsOpen
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
confluentinc/confluent-sql#124 ·
Maintainers usually reply within 1 day
All issues in confluentinc/confluent-sql
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
topoteretes/cognee#5647 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Sendspin/sendspin-python-cli#291 ·
Maintainers usually reply within 6 days
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
awslabs/visual-asset-management-system#414 ·
Maintainers usually reply within 1 day
-
bug v1 v2
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
modelcontextprotocol/python-sdk#3670 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
aicell-lab/bioengine#232 ·
Maintainers usually reply within 1 day