Skip to content

Fix OIDC token refresh failing on Windows when idp-certificate-authority-data is set#2644

Open
ealeonraz wants to merge 1 commit into
kubernetes-client:masterfrom
ealeonraz:fix-oidc-refresh-tempfile-windows
Open

Fix OIDC token refresh failing on Windows when idp-certificate-authority-data is set#2644
ealeonraz wants to merge 1 commit into
kubernetes-client:masterfrom
ealeonraz:fix-oidc-refresh-tempfile-windows

Conversation

@ealeonraz

@ealeonraz ealeonraz commented Jul 21, 2026

Copy link
Copy Markdown

What this does

KubeConfigLoader._refresh_oidc wrote the IdP CA certificate by creating a tempfile.NamedTemporaryFile(delete=True) and then re-opening it by name. On Windows that second open raises PermissionError (the file is held exclusively while open), so OIDC token refresh fails at runtime for any kubeconfig using idp-certificate-authority-data. This is the temp-file portion of #2427.

The fix reuses the module's existing _create_temp_file_with_content helper (mkstemp-based, closed before reuse, cleaned up via the existing atexit handler) — the same mechanism this file already uses for other inline certificate data, so behavior is now consistent across platforms and cleanup no longer depends on GC timing.

Testing

pytest kubernetes/base/config/kube_config_test.py on Windows 11: 75 passed — including test_oidc_with_refresh, which fails with PermissionError before this change. No test modifications were needed; the existing tests cover the path once the production code is fixed.

Ref #2427 — planned as the first of a short series of small Windows fixes discussed there.

Fixed OIDC token refresh failing with PermissionError on Windows when the kubeconfig uses idp-certificate-authority-data.

_refresh_oidc wrote the IdP CA certificate by reopening a
NamedTemporaryFile by name, which raises PermissionError on Windows
while the original handle is still open. Reuse the module's existing
_create_temp_file_with_content helper, which is mkstemp-based
(Windows-safe) and cleans up via atexit instead of relying on GC
timing.
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: ealeonraz
Once this PR has been reviewed and has the lgtm label, please assign yliaog for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow
kubernetes-prow Bot requested review from fabianvf and yliaog July 21, 2026 06:46
@linux-foundation-easycla

linux-foundation-easycla Bot commented Jul 21, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: ealeonraz / name: ealeonraz (b027171)

@kubernetes-prow kubernetes-prow Bot added needs-kind Indicates a PR lacks a `kind/foo` label and requires one. cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels Jul 21, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

Welcome @ealeonraz!

It looks like this is your first PR to kubernetes-client/python 🎉. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes-client/python has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 😃

@kubernetes-prow kubernetes-prow Bot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. release-note Denotes a PR that will be considered when it comes time to generate release notes. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. and removed do-not-merge/release-note-label-needed Indicates that a PR should not merge because it's missing one of the release note labels. cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels Jul 21, 2026
@ealeonraz

Copy link
Copy Markdown
Author

/kind bug

@kubernetes-prow kubernetes-prow Bot added kind/bug Categorizes issue or PR as related to a bug. and removed needs-kind Indicates a PR lacks a `kind/foo` label and requires one. labels Jul 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/bug Categorizes issue or PR as related to a bug. release-note Denotes a PR that will be considered when it comes time to generate release notes. size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant