Broken websocket client on custom authorization header names
Maintainer thường phản hồi trong vòng 3 ngày
@Sanil2108 đang làm issue này rồi.
Từ ngày 14/2/2026.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
What happened (please include outputs or screenshots):
We use Kubernetes in our production, as per the security regulation, the API server requires a custom authorization header, say "MY-AUTH-TOKEN", instead of the default header name "Authorization". The token is more secure than the static service account token.
The kubernetes.client.configuration.Configuration class doesn't support the custom header name, but we can play a hack to workaround this:
from kubernetes import client
class MyConfiguration(client.Configuration):
def auth_settings(self):
auth = {}
if 'authorization' in self.api_key:
auth['BearerToken'] = {
'type': 'api_key',
'in': 'header',
'key': 'MY-AUTH-TOKEN', # set header name here
'value': self.get_api_key_with_prefix('authorization')
}
return auth
# usage
my_cfg = MyConfiguration(...)
v1 = client.CoreV1Api(client.ApiClient(my_cfg))
pod = v1.read_namespaced_pod('my-pod', 'my-ns')
However, this hack doesn't work on the kubernetes.stream.stream() call, the reason is the websocket client doesn't hornor the "auth_settings" in the configuration.
(code snippet in kubernetes.stream.ws_client.py)
def create_websocket(configuration, url, headers=None):
enableTrace(False)
# We just need to pass the Authorization, ignore all the other
# http headers we get from the generated code
header = []
if headers and 'authorization' in headers:
header.append("authorization: %s" % headers['authorization'])
...
Here the header name is hard coded as "authorization", any other custom headers are discarded.
As a result, the stream() call breaks, this breaks watching and exec.
What you expected to happen:
The websocket client should handle the auth headers in the same way as api client, see ApiClient.update_params_for_auth() impl.
The configuration object is passed in as the first parameter of create_websocket function, it has the ability to get the header name by calling configuration.auth_settings()["key"]
def create_websocket(configuration, url, headers=None):
enableTrace(False)
# We just need to pass the Authorization, ignore all the other
# http headers we get from the generated code
header = []
auth_settings = configuration.auth_settings().get('BearerToken')
if auth_settings:
if auth_settings['in'] == 'cookie':
header.append("Cookie: %s" % auth_settings['value'])
elif auth_settings['in'] == 'header':
header.append("%s: %s" % (auth_settings['key'], auth_settings['value']))
...
How to reproduce it (as minimally and precisely as possible):
Anything else we need to know?:
Environment:
- Kubernetes version (
kubectl version):
Any - OS (e.g., MacOS 10.13.6):
Any - Python version (
python --version)
Any - Python client version (
pip list | grep kubernetes)
This issue exists on all client versions.
- Ngôn ngữ chính
- Python
- Star
- 7.7k
- Fork
- 3.5k
- Merge trung bình
- 3 ngày 4 giờ
- Pull request đã merge (30 ngày)
- 9
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của kubernetes-client/python
-
getheaders is deprecated in urllib3 >= 2.0.0Có thể làm lại được Pull request cho issue này đã bị đóng mà không được merge. Đang mởkind/bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 68/100
kubernetes-client/python#2280 · 16 bình luận · 9 reaction ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Security: pin oauthlib>=4.0.0 (CVE-2026-49264, CVE-2026-49265)Có thể đã có người làm @friedrichwilken đã nhận 3 ngày trước. Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 30/100
kubernetes-client/python#2720 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Release 1.37Có thể làm lại được @yliaog đã nhận 37 ngày trước và không có pull request nào đang mở. Đang mở
kubernetes-client/python#2691 · 1 bình luận · 1 reaction · 1 người được giao ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Growing library sizeĐang mởhelp wanted
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
kubernetes-client/python#2677 · 14 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Add option to disable strict x509 verifcation in sync clientCó thể đã có người làm @Vishwa0223 đã nhận 41 ngày trước. Đang mởhelp wanted kind/feature
kubernetes-client/python#2602 · 6 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 3 ngày
Tất cả issue của kubernetes-client/python
Issue tương tự
-
json_params_matcher fails on falsy top-level JSON primitives (0, False, "")Có thể đã có người làm @mayureshsonawane17 đã nhận hôm nay. Đang mởWaiting for: Product Owner
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 5 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Maintainer thường phản hồi trong vòng 1 ngày
-
第二章思考题 8:Skill 追加到末尾不必每轮重新计算 KVĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
bojieli/ai-agent-book#1169 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
priority:low ready-for-dev
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
OpenHands/extensions#738 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
micronaut-projects/micronaut-core#13677 ·
Maintainer thường phản hồi trong vòng 1 ngày