Broken websocket client on custom authorization header names
Los mantenedores suelen responder en 2 días
@Sanil2108 ya está trabajando en esto.
Desde el 14/2/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
What happened (please include outputs or screenshots):
We use Kubernetes in our production, as per the security regulation, the API server requires a custom authorization header, say "MY-AUTH-TOKEN", instead of the default header name "Authorization". The token is more secure than the static service account token.
The kubernetes.client.configuration.Configuration class doesn't support the custom header name, but we can play a hack to workaround this:
from kubernetes import client
class MyConfiguration(client.Configuration):
def auth_settings(self):
auth = {}
if 'authorization' in self.api_key:
auth['BearerToken'] = {
'type': 'api_key',
'in': 'header',
'key': 'MY-AUTH-TOKEN', # set header name here
'value': self.get_api_key_with_prefix('authorization')
}
return auth
# usage
my_cfg = MyConfiguration(...)
v1 = client.CoreV1Api(client.ApiClient(my_cfg))
pod = v1.read_namespaced_pod('my-pod', 'my-ns')
However, this hack doesn't work on the kubernetes.stream.stream() call, the reason is the websocket client doesn't hornor the "auth_settings" in the configuration.
(code snippet in kubernetes.stream.ws_client.py)
def create_websocket(configuration, url, headers=None):
enableTrace(False)
# We just need to pass the Authorization, ignore all the other
# http headers we get from the generated code
header = []
if headers and 'authorization' in headers:
header.append("authorization: %s" % headers['authorization'])
...
Here the header name is hard coded as "authorization", any other custom headers are discarded.
As a result, the stream() call breaks, this breaks watching and exec.
What you expected to happen:
The websocket client should handle the auth headers in the same way as api client, see ApiClient.update_params_for_auth() impl.
The configuration object is passed in as the first parameter of create_websocket function, it has the ability to get the header name by calling configuration.auth_settings()["key"]
def create_websocket(configuration, url, headers=None):
enableTrace(False)
# We just need to pass the Authorization, ignore all the other
# http headers we get from the generated code
header = []
auth_settings = configuration.auth_settings().get('BearerToken')
if auth_settings:
if auth_settings['in'] == 'cookie':
header.append("Cookie: %s" % auth_settings['value'])
elif auth_settings['in'] == 'header':
header.append("%s: %s" % (auth_settings['key'], auth_settings['value']))
...
How to reproduce it (as minimally and precisely as possible):
Anything else we need to know?:
Environment:
- Kubernetes version (
kubectl version):
Any - OS (e.g., MacOS 10.13.6):
Any - Python version (
python --version)
Any - Python client version (
pip list | grep kubernetes)
This issue exists on all client versions.
- Lenguaje dominante
- Python
- Estrellas
- 7.7k
- Forks
- 3.5k
- Merge medio
- 2 d 10 h
- PR fusionados (30 d)
- 19
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de kubernetes-client/python
-
kind/bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 68/100
kubernetes-client/python#2280 · 16 comentarios · 9 reacciones ·
Los mantenedores suelen responder en 2 días
-
Release 1.37Quizá libre de nuevo @yliaog la tomó hace 33 días y no hay ningún pull request abierto. Abierto
kubernetes-client/python#2691 · 1 comentario · 1 reacción · 1 asignado ·
Los mantenedores suelen responder en 2 días
-
Growing library sizeAbiertohelp wanted
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
kubernetes-client/python#2677 · 14 comentarios · 1 reacción ·
Los mantenedores suelen responder en 2 días
-
Add option to disable strict x509 verifcation in sync clientQuizá libre de nuevo @Vishwa0223 la tomó hace 38 días y no hay ningún pull request abierto. Abiertohelp wanted kind/feature
kubernetes-client/python#2602 · 6 comentarios · 1 asignado ·
Los mantenedores suelen responder en 2 días
-
v36.0.0 regression fetching container logsQuizá libre de nuevo @yliaog la tomó hace 76 días y no hay ningún pull request abierto. Abiertokind/bug
kubernetes-client/python#2596 · 14 comentarios · 2 reacciones · 1 asignado ·
Los mantenedores suelen responder en 2 días
Todos los issues de kubernetes-client/python
Issues similares
-
repo-audit
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
scverse/repo-health#20 ·
Los mantenedores suelen responder en 1 día
-
/context/prime scope override double-prefixes an entity-ref project and drops its scoped memoriesAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
phasespace-labs/palinode#232 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
collective/icalendar#1858 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
lfx-mcp cannot supply global variables: LangflowClient drops X-LANGFLOW-GLOBAL-VAR-* from envAbiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
langflow-ai/langflow#15496 ·
Los mantenedores suelen responder en 1 día