Skip to content

Draft: add typed service-account certificate identity contract - #168

Draft
rkoster wants to merge 6 commits into
cloudfoundry:mainfrom
rkoster:service-accounts-poc
Draft

rkoster wants to merge 6 commits into
cloudfoundry:mainfrom
rkoster:service-accounts-poc

Conversation

@rkoster

@rkoster rkoster commented Oct 6, 2026 •

Copy link
Copy Markdown

Summary

Community RFC draft: cloudfoundry/community#1645.

Draft authoritative BBS contract for the service-account proposal, consumed by companion CAPI and Diego implementations.

  • Add optional CertificateProperties.service_account at protobuf field 2 and ServiceAccount.name at field 1; retain existing organizational-unit field 1.
  • Regenerate Go bindings from the authoritative protobuf source.
  • Validate canonical lowercase 3–63-character DNS-label account names through certificate properties, desired LRP run-info and task definition validation. Existing account-free properties remain valid.
  • Preserve certificate properties in DesiredLRP.AddRunInfo when assembling stored desired LRPs; without this, the identity is dropped before rep sees it.
  • Cover JSON/protobuf round trips, invalid names, LRP/task validation and stored-LRP assembly.

This is a platform-owned launch identity contract, not an app-supplied SAN API. CAPI owns authorization/same-space assignment; Diego derives <name>.svc.identity and protects the reserved namespace. The revised proposal uses space-owned accounts.

Verification and history

Committed TDD cycles:

  • Round trip RED cab068e → GREEN 1b8b954.
  • Canonical validation RED 680b730 → GREEN bd154ac.
  • Stored-LRP assembly RED 1a660ab → GREEN 869b065.

Focused contract tests and full models regressions passed. Companion Diego wire → stored LRP → rep → real certificate tests and live two-app/runtime-task evidence exercise this exact contract. Go/Ruby bindings and Diego vendor were generated from this source, not manually edited.

# From models/
go test . -run 'TestServiceAccount|TestAssembledDesiredLRP' -count=1
go test ./...

Compatibility and draft dependency

Optional protobuf additions preserve account-free wire compatibility, but old components may discard unknown fields. Automatic capability negotiation is not implemented; the companion CAPI/Diego operator gates require all participating components to be upgraded before launching account-bound workloads.

Companion Diego currently pins code.cloudfoundry.org/bbs/models to v1.15.1-0.20261005213824-869b0650f414 at source head 869b0650f4147bb24d790f52153ef571fc11bda0. Publishing this draft makes source reviewable, but the code.cloudfoundry.org module version still needs upstream publication/alignment before consumers can refresh dependencies normally. No tags/releases are created by this draft.

Companion drafts: cloud_controller_ng #5520, capi-release #702, Diego #1216, CLI #3875. This contract is experimental and does not itself implement UAA token policy or route authorization.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

1 participant