RemoteA2aAgent enforces HTTPS for agent cards, blocking plaintext A2A inside a service mesh (mTLS)
メンテナーはふだん 5 日以内に返信
@surajksharma07 がすでに取り組んでいます。
2026年9月16日 から。
評価
この issue はまだ評価されていません。
説明
What happened
RemoteA2aAgent enforces that an agent card's URL — and every RPC target URL inside the resolved card — must be https, unless the host is loopback. This is enforced client-side in src/google/adk/agents/remote_a2a_agent.py (ADK 2.9.1):
_resolve_agent_card()rejects a non-loopbackhttp://card source URL with:Agent card URL must use https, or http on a loopback host: <url>_validate_card_rpc_targets()rejects a resolved card whose RPC target URLs are non-loopbackhttp://with:Agent card RPC URL must use https, or http on a loopback host: <url>
(_is_loopback_host() only permits localhost, *.localhost, and loopback IPs.) There doesn't appear to be an opt-out (flag, config field, or env var).
Why this is a problem: A2A inside a service mesh (mTLS)
A very common production topology for multi-agent A2A is Kubernetes + a service mesh (Istio / Cloud Service Mesh, Linkerd) with STRICT mTLS. In that model:
- The application speaks plaintext
http://to the peer's in-cluster DNS name (e.g.http://research.agents.svc.cluster.local/a2a/app/...). - The sidecar proxy transparently upgrades every hop to mTLS, and authorization is enforced by mesh identity (SPIFFE) +
AuthorizationPolicy.
This is the mesh's entire design: apps stay plaintext, the mesh provides confidentiality + peer authentication. But ADK's client-side gate refuses plaintext to non-loopback hosts, so the first delegation fails at card resolution with AgentCardResolutionError. The security property the https requirement stands in for (no plaintext MITM) is already guaranteed by the mesh — so the gate is redundant here, yet there's no way to say so.
Minimal repro
from google.adk.agents.remote_a2a_agent import RemoteA2aAgent
# Non-loopback http card URL — realistic in-cluster A2A address behind a mesh.
agent = RemoteA2aAgent(
name="research",
agent_card="http://research.agents.svc.cluster.local/a2a/app/.well-known/agent-card.json",
)
# On first use -> AgentCardResolutionError:
# "Agent card URL must use https, or http on a loopback host: ..."
The underlying transport is fine with http — only this ADK-level check blocks it.
Current workaround (and why it's not great)
Passing a pre-constructed AgentCard object (rather than a URL/file source) skips both checks — _validate_card_rpc_targets() returns early when there is no http(s) source, and _resolve_agent_card() is never called — so the plaintext POST then flows and the mesh wraps it in mTLS. But this forces callers to give up ADK's lazy live-card fetch and hand-build/hard-code the card + RPC URL, which is exactly the discovery ADK otherwise does for you.
What we'd like to discuss
Would the maintainers be open to an opt-in escape hatch so operators who know they're inside a trusted transport (a mesh) can allow non-loopback http? A few shapes, from least to most granular:
- A per-instance flag, e.g.
RemoteA2aAgent(..., allow_insecure_http=True)(or onA2aRemoteAgentConfig), applied to both the card fetch and the RPC-target validation. - An env / global toggle (e.g.
ADK_A2A_ALLOW_INSECURE_HTTP=1) for cluster-wide deployments. - A configurable trusted-host / CIDR allowlist that widens the loopback carve-out.
Opt-in (default stays https-only) keeps the secure-by-default behavior while unblocking the mesh use case. Happy to send a PR if you can point me at the preferred shape.
Environment
google-adk2.9.1- Deployment: GKE + Cloud Service Mesh (managed Istio), namespace-wide STRICT
PeerAuthentication - A2A over
RemoteA2aAgentwith in-cluster DNS peer URLs
- 主要言語
- Python
- スター
- 21.6k
- フォーク
- 4k
- 平均マージ
- 12時間 6分
- マージ済み PR(30日)
- 4
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
google/adk-python のほかの issue
-
[A2A] RemoteA2aAgent(use_legacy=False): extension header written to state['http_kwargs'], ignored by a2a-sdk 1.x transports対応中かも @surajksharma07 が 3 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
google/adk-python#7334 · コメント 2 件 · 担当者 1 名 ·
メンテナーはふだん 5 日以内に返信
-
GoogleOidcVerifier treats string "false" as a verified email claim対応中かも @surajksharma07 が 4 日前に担当しました。 オープンcore
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
google/adk-python#7289 · コメント 5 件 · 担当者 1 名 ·
メンテナーはふだん 5 日以内に返信
-
RestApiTool raises uncaught KeyError when a required path param is omitted対応中かも @llalitkumarrr が 4 日前に担当しました。 オープンrequest clarification tools
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
google/adk-python#7282 · コメント 5 件 · 担当者 1 名 ·
メンテナーはふだん 5 日以内に返信
-
CredentialsManager should also extract scopes when populating auth schemes対応中かも @sanketpatil06 が 7 日前に担当しました。 オープンcore needs review
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
google/adk-python#7266 · コメント 2 件 · 担当者 1 名 ·
メンテナーはふだん 5 日以内に返信
-
OAuth2 Discovery method fails because FastMCP with GoogleProvider (OAuth) returns issuerUrl with trailing slash対応中かも @sanketpatil06 が 7 日前に担当しました。 オープンmcp
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
google/adk-python#7265 · コメント 4 件 · 担当者 1 名 ·
メンテナーはふだん 5 日以内に返信
google/adk-python の issue をすべて見る
似ている issue
-
New Internshipオープンnew_internship
難易度 1/5 1時間未満 初心者へのやさしさ 70/100
-
[BUG] Reports tab: "Unban" button tooltip shows raw `{{ip}}` placeholder instead of the IP addressオープンbug javascript ui
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
bunkerity/bunkerweb#4001 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
PedestrianDynamics/pyFDS-Evac#476 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
google/differential-privacy#516 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
adobe-fonts/source-serif#153 ·