Spinnaker 2025.4: Bearer token API auth breaks after Spring Boot 3
Shows how to fix spinnaker 2025.4: Bearer token API auth breaks after Spring Boot 3. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.
TL;DR
Migrate your auth config to the Spring Security 5 OAuth2 format described in the 2025.2.0 changelog, placing the adjusted gate-local.yml in your halyard profiles. A maintainer explains the required migration: switch to spring-style configuration per the 2025.2.0 changelog.
Steps
- Migrate your auth config to the Spring Security 5 OAuth2 format described in the 2025.2.0 changelog, placing the adjusted gate-local.yml in your halyard profiles. Halyard old-style oauth2 settings will not work with the new stack. The redirect fix in PR #7380 covers the login redirect piece; the gate-local.yml migration covers the bearer validation piece.
When to use
You are seeing this: Halyard old-style oauth2 settings will not work with the new stack. Use this skill when you run into "Spinnaker 2025.4: Bearer token API auth breaks after Spring Boot 3".
When not to use
If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.
Versions
Versions mentioned in the source: 2025.2.0, 2025.4.0. If you are on something much newer or older, the details may have shifted.
Why this happens
The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.