Skip to main content

add `use` field to .well-known/jwks for oidc

Dear support,

I tried to integrate spacelift with aliyun oidc, (i understand this is not official documented), and it failed at checking oidc discovery of the issuer url. According to aliyun support, it is likely because the keys in

.well-known/jwks has no “use” filed. I understand that this field is optional in spec, but it could help to support aliyun if the field is presented. Thanks

Workaround
no
Problem
Status: ✅ Completed3 comments

Log in to comment and vote

Comments3

  • Black Breeze

    •

    Jan 13

    Hello @何梓為 (開發營運部)Kaga He ! Thanks for raising this. Can you please point me to the documentation that mentions the `use` field as a requirement for Aliyun OIDC? Please bear with me, I’m not very familiar with that particular cloud provider. Thank you in advance!

    • Black Stream

      •

      Jan 14

      hello @Marcin Wyszynski ! Thanks for the reply.

      Good question. I actually couldn't find a specific page in the Aliyun docs that lists this as a hard requirement either.

      My request is mainly based on a process of elimination:

      1. Alibaba Cloud support mentioned to me that the missing use field is likely why the validation is failing.

      2. I did a side-by-side comparison with a working GitHub OIDC setup, and the main difference I found was that GitHub includes the use field while Aliyun doesn't.

      I’m treating this as a likely fix for the current broken state rather than a documented spec requirement. Thanks for bearing with me on this!

    • Black Stream

      •

      Jan 16

      hello @Marcin Wyszynski ! I can see the update when I am reviewing today, and I can successfully add spacelift oidc to aliyun now. I will further test integration soon. Thanks for the quick update first!!