Skip to content

Allow cloudflare service tokens to be allowed list through epoxy#19

Open
MFMarkus wants to merge 1 commit intomasterfrom
allow-service-token
Open

Allow cloudflare service tokens to be allowed list through epoxy#19
MFMarkus wants to merge 1 commit intomasterfrom
allow-service-token

Conversation

@MFMarkus
Copy link
Contributor

@MFMarkus MFMarkus commented Feb 25, 2026

Basis for this PR is that we want to fetch info from Cussos admin endpoints like users and organizations to allow easier setup in MFN/Slog.

Cussos admin web is behind Cloudflare Zero Trust.

Cloudflare has service tokens that serve this purpose quite well.

However, Cussos admin also has epoxy, which will block these when doing the external lookup to our directory.

So we need to bypass this directory lookup for service tokens.

An alternative is exposing endpoints with a non epoxy middleware in Cussos and then doing the standard pub/priv key exchange between services. However I thought this could be a neat alternative that can be used for other zero auth flows aswell without having to setup new keypairs?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant