#6972·spinnaker

Authenticated requests fail when too many accounts in X-SPINNAKER-ACCOUNTS

Author: pjberry16Created Aug 26, 2024Updated Jan 23, 2025
Labelsenhancementauthno-lifecyclecontributions welcomehas workaround

Issue Summary:

When a lot of Spinnaker accounts are added the X-SPINNAKER-ACCOUNTS header gets too large causing the max header size to continuously need to be increased as more accounts are added to Spinnaker.

Feature Area:

clouddriver, orca, fiat

Description:

As the number of Spinnaker accounts scales, calls should continue to function as normal without needing to increase max header size. Instead, once the Spinnaker accounts gets too long authenticated calls fail with a "Request Header Fields Too Large" error.

Steps to Reproduce:

Set max header size to a smaller size than the size of accounts and have an admin make an authenticated call. The X-SPINNAKER-ACCOUNTS header will be larger than max header size and the call will fail with a "Request Header Fields Too Large" error.

Additional Details:

Admins in Spinnaker have access to all accounts leading to a long X-SPINNAKER-ACCOUNTS header. A better solution could be to call Fiat to check allowed accounts instead of checking the contents of the header.