Skip to content

Add selective retries for STS token exchange#532

Open
blalor wants to merge 1 commit into
google-github-actions:mainfrom
blalor:sts-token-exchange-retries
Open

Add selective retries for STS token exchange#532
blalor wants to merge 1 commit into
google-github-actions:mainfrom
blalor:sts-token-exchange-retries

Conversation

@blalor

@blalor blalor commented Jul 21, 2026

Copy link
Copy Markdown

Summary

The workload identity flow retries GitHub OIDC token retrieval, but @actions/http-client does not retry the POST to Google Security Token Service. A transient connection reset or socket timeout therefore ends authentication on the first failed exchange.

This change adds four bounded STS attempts with 100, 200, and 400 ms backoffs. Retries are limited to connection failures and HTTP 408, 429, 500, 502, 503, and 504 responses. HTTP 400, 401, 403, empty responses, and unknown errors fail without retrying.

Attempt diagnostics contain only the operation, STS hostname, status or classified error, and attempt count. The existing STS request and computed-audience debug messages were removed so these diagnostics do not include the OIDC assertion, returned access token, headers, credential data, service account, or workload identity provider resource.

Mocked tests cover each retryable HTTP status, connection errors, the uncoded @actions/http-client socket timeout, permanent HTTP failures, the four-attempt limit, and diagnostic redaction.

@google-cla

google-cla Bot commented Jul 21, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@blalor
blalor marked this pull request as ready for review July 21, 2026 17:36
@blalor
blalor requested a review from a team as a code owner July 21, 2026 17:36
@blalor
blalor requested review from R2wenD2 and kkarrenn July 21, 2026 17:36
@blalor
blalor marked this pull request as draft July 21, 2026 18:39
@blalor
blalor marked this pull request as ready for review July 21, 2026 21:00
import { AuthClient, Client, ClientParameters } from './client';

const STS_MAX_ATTEMPTS = 4;
const STS_RETRY_BACKOFF_MILLISECONDS = 100;

@kkarrenn kkarrenn Jul 24, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A delay of <1 second across all 4 attempts might be too short to see the backend to recover.

Please, consider bumping the base backoff up. For example, using a 500ms base will provide delays of 500ms, 1s, 2s, which buys a more resilient 3.5 seconds for the backend to recover.

Comment on lines +191 to +193
`Failed to generate Google Cloud federated token: operation=token_exchange, ` +
`endpoint_class=${endpoint}, status=${status}, ` +
`error_class=${failure.errorClass}, attempt=${attempt}/${STS_MAX_ATTEMPTS}`,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hiding the entire resp.result object here makes a lot of sense.

Including resp.result?.error_description || resp.result?.error?.message shouldn't harm and will provide more insights into the error.

@kkarrenn kkarrenn left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for this PR! Added a couple of comments below.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants