Repository navigation
Conversation
…tage When an agent's clock runs ahead of the controller's by more than the 10 s JWT tolerance, every request it signs fails verification with JWTClaimValidationFailed on the "nbf" or "iat" claim. The controller mapped that to a generic authentication failure, so the agent's log said the controller was unreachable or unauthorised and the real cause -- a clock a few seconds ahead -- was nowhere in either log. Measured on Controller 3.8.2 with Edgelet v1.0.3-rc.1 and a deliberate +24 h step on the node: reconciliation stalled and neither side named the clock. This classifies those two claim failures as a retryable ServiceUnavailableError with a new CONTROLLER_AGENT_CLOCK_SKEW code and the message "Agent clock is ahead of the controller: ...". Retryable is deliberate, and unchanged from today's behaviour in effect: an agent that receives non-retryable auth failures deprovisions itself after five attempts (edgelet internal/fieldagent/status_auth_gate.go), which would turn a few seconds of drift into a node that must be bootstrapped again. Only the diagnosis was missing. Signed-off-by: Nilson.Henao <nilsonfh@gmail.com> Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this fixes
When an agent's clock runs ahead of the Controller's by more than the 10 s JWT
tolerance, every request it signs fails verification with
JWTClaimValidationFailedon the
"nbf"or"iat"claim. Today that is mapped to a generic authenticationfailure, so the agent logs what looks like an unreachable or unauthorised Controller
and neither side names the real cause.
This adds a
CONTROLLER_AGENT_CLOCK_SKEWcode and classifies those two claim failuresas a retryable
ServiceUnavailableErrorwith the messageAgent clock is ahead of the controller: <detail>.Why retryable, deliberately
Retryable keeps today's effective behaviour. An agent that receives non-retryable auth
failures deprovisions itself after five attempts (Edgelet
internal/fieldagent/status_auth_gate.go), which would turn a few seconds of driftinto a node that has to be bootstrapped again. Retrying is right; only the diagnosis
was missing.
How it was found
Measured on Controller 3.8.2 with Edgelet v1.0.3-rc.1, stepping a node's clock +24 h
on purpose as part of a scripted partition test. Reconciliation stalled and no log on
either side mentioned the clock; the cause was found by reading the JWT claims. With
this change the Controller says which node's clock is ahead and by what claim.
Scope and risk
Two files, 16 added lines, no API change: an additional error code and one branch in
the existing classification helper. Requests that were retried are still retried.
Verification
npx standard@17clean on both changed files (same version as the repo'sdevDependency).
Note:
npm cifails ondevelopfor an unrelated reason (ERESOLVE:sinon-chai@3.7.0wantschai@">=2.1.2 <6", the tree haschai@5.1.1viachai-as-promised), so the test suite was not run here.🤖 Generated with Claude Code