Repository navigation
Conversation
This was referenced Oct 6, 2026
Draft
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Community RFC draft: cloudfoundry/community#1645.
Draft authoritative BBS contract for the service-account proposal, consumed by companion CAPI and Diego implementations.
CertificateProperties.service_accountat protobuf field 2 andServiceAccount.nameat field 1; retain existing organizational-unit field 1.DesiredLRP.AddRunInfowhen assembling stored desired LRPs; without this, the identity is dropped before rep sees it.This is a platform-owned launch identity contract, not an app-supplied SAN API. CAPI owns authorization/same-space assignment; Diego derives
<name>.svc.identityand protects the reserved namespace. The revised proposal uses space-owned accounts.Verification and history
Committed TDD cycles:
cab068e→ GREEN1b8b954.680b730→ GREENbd154ac.1a660ab→ GREEN869b065.Focused contract tests and full models regressions passed. Companion Diego wire → stored LRP → rep → real certificate tests and live two-app/runtime-task evidence exercise this exact contract. Go/Ruby bindings and Diego vendor were generated from this source, not manually edited.
Compatibility and draft dependency
Optional protobuf additions preserve account-free wire compatibility, but old components may discard unknown fields. Automatic capability negotiation is not implemented; the companion CAPI/Diego operator gates require all participating components to be upgraded before launching account-bound workloads.
Companion Diego currently pins
code.cloudfoundry.org/bbs/modelstov1.15.1-0.20261005213824-869b0650f414at source head869b0650f4147bb24d790f52153ef571fc11bda0. Publishing this draft makes source reviewable, but thecode.cloudfoundry.orgmodule version still needs upstream publication/alignment before consumers can refresh dependencies normally. No tags/releases are created by this draft.Companion drafts: cloud_controller_ng #5520, capi-release #702, Diego #1216, CLI #3875. This contract is experimental and does not itself implement UAA token policy or route authorization.