Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Can the Coder Agent send along an additional header to bypass an identity aware proxy? #14412

Closed
Labels
need-helpAssign this label prompts an engineer to check the issue. Only humans may set this.securityArea: security
@mike-sol

Description

@mike-sol

I have a Coder instance that is presently happily sitting behind an AWS ALB using the AWS Cognito integration for authentication. This links to my IDP and so all connections through to Coder are authenticated before any service that I run is exposed to the internet. I believe this configuration is commonly called an "Identity Aware Proxy", though the proxying action is very transparent and is part of the ALB.

(This is independant of Coder itself being set up for OIDC separately with the same IDP).

This works brilliantly in the browser, but not so much for Coder workspaces that are not in the same private VPC network as the Coder server, as if they want to be able to call back to Coder via the external ACCESS_URL, they can't get past the authentication requirement.

I can bypass this by using simple methods like IP whitelisting (not possible for my use case) or a header, e.g. a bearer token authentication.

Is there any way to get the Coder agent to send along an additional header that I can use to secure the connection and bypass the need to redirect to browser-interactive SSO?

Failing this, what is the general recommendation for securing a Coder instance exposed to the raw Internet? Is running a WAF with some automatic detection package generally recommended?

Metadata

Metadata

Assignees

No one assigned

    Labels

    need-helpAssign this label prompts an engineer to check the issue. Only humans may set this.securityArea: security

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions


      [8]ページ先頭

      ©2009-2025 Movatter.jp