Skip to content

Add selective retries for STS token exchange - #532

Merged
kkarrenn merged 2 commits into
google-github-actions:mainfrom
blalor:sts-token-exchange-retries
Jul 29, 2026
Merged

kkarrenn merged 2 commits into
google-github-actions:mainfrom
blalor:sts-token-exchange-retries

Conversation

@blalor

@blalor blalor commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Summary

The workload identity flow retries GitHub OIDC token retrieval, but @actions/http-client does not retry the POST to Google Security Token Service. A transient connection reset or socket timeout therefore ends authentication on the first failed exchange.

This change adds four bounded STS attempts with 100, 200, and 400 ms backoffs. Retries are limited to connection failures and HTTP 408, 429, 500, 502, 503, and 504 responses. HTTP 400, 401, 403, empty responses, and unknown errors fail without retrying.

Attempt diagnostics contain only the operation, STS hostname, status or classified error, and attempt count. The existing STS request and computed-audience debug messages were removed so these diagnostics do not include the OIDC assertion, returned access token, headers, credential data, service account, or workload identity provider resource.

Mocked tests cover each retryable HTTP status, connection errors, the uncoded @actions/http-client socket timeout, permanent HTTP failures, the four-attempt limit, and diagnostic redaction.

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants