maqpna-identity
The identity broker: mints the short-lived session tokens the gateway verifies.
Server binaries
Synopsis#
Flags#
| Flag | Type | Description | Default |
|---|
-audience | string | default token audience (aud) | maqpna-gateway |
-bootstrap-audience | string | audience of the projected ServiceAccount tokens presented to /v1/bootstrap | maqpna-bootstrap |
-bootstrap-listen | string | listen address of the warm-pool bootstrap endpoint (POST /v1/bootstrap; needs in-cluster API access); empty = disabled | none |
-default-ttl | duration | token lifetime when ttlSeconds is 0 | 15m0s |
-exchange-config | string | JSON allowlist of token-exchange audiences | none |
-generate-key | switch | generate the signing key if -key does not exist | none |
-issuer | string | token issuer (iss) | maqpna-identity |
-key | string | Ed25519 signing key (PKCS#8 PEM) | /var/run/maqpna/identity/identity.key |
-listen | string | listen address | :8081 |
-max-delegation-depth | int | maximum act-chain depth of A2A delegation tokens | 5 |
-max-ttl | duration | maximum token lifetime | 1h0m0s |
-previous-keys | string | comma-separated PEM files of retired-but-trusted public keys (rotation) | none |
-sandbox-api-version | string | agent-sandbox API version (Sandbox / SandboxClaim) | v1beta1 |
-tenant-keys-dir | string | directory of <tenant>.pem signing keys (Secret maqpna-tenant-keys) | /var/run/maqpna/tenant-keys |
-tenant-reload | duration | how often -tenants-file and -tenant-keys-dir are re-read | 10s |
-tenants-file | string | tenants.json (ConfigMap maqpna-tenants): sign tenant namespaces' tokens with per-tenant keys (F-27) | none |
-trust-domain | string | SPIFFE trust domain | maqpna.local |
-txn-token-audience | string | expected Transaction Token audience (default: the trust domain) | none |
-txn-token-keys | string | comma-separated PEM public keys trusted for Transaction Tokens used as A2A delegation subjects (the broker key is always trusted) | none |
-version | switch | print version and exit | none |
What happens when you run it#
- A long-running server. The Helm chart starts it with these flags; set them through the chart's values rather than by hand.
Exit codes#
| Code | Meaning |
|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
Terminal demo#
maqpna-identity -h.cast