Skip to content

Draft: wire service-account provisioning and runtime gates - #702

Draft
rkoster wants to merge 13 commits into
cloudfoundry:developfrom
rkoster:service-accounts-poc
Draft

rkoster wants to merge 13 commits into
cloudfoundry:developfrom
rkoster:service-accounts-poc

Conversation

@rkoster

@rkoster rkoster commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Community RFC draft: cloudfoundry/community#1645.

Draft BOSH wiring for the service-account proposal and companion cloud_controller_ng implementation.

  • Declare/render default-off cc.service_accounts.provisioning_enabled and runtime_enabled gates and non-secret token endpoint discovery.
  • Render a dedicated management client ID/secret and instance-identity trust anchor only into enabled workers. API templates expose gates/discovery, not provisioning credentials.
  • Supply runtime discovery to clock-driven reconciliation.
  • Render cc.service_accounts.creation_limit (default -1/unlimited), the rolling seven-day creation budget per non-admin principal across the foundation; admins, including admin automation, are exempt.
  • Pin cloud_controller_ng to tested source ec582b703ef80fa9b9c5b3c34ca2798a29b4b801, including creation-budget enforcement and cascading account cleanup during space/org deletion.
  • Make copied application directories readable by the unprivileged runtime user; this fixes a concrete prestart failure from private archive-parent modes during lab builds.

Verification

  • Committed RED/GREEN template cycles: worker e7231e01 → 84b18957; API bd7d8831 → 333cda02; clock ed47d221 → 7dbf40bb.
  • Budget template RED fbd0c3ed → GREEN e2a5bce2; 110 API/worker/clock release-template examples passed.
  • Built/uploaded/deployed timestamped lab releases with these templates. Latest CAPI lab release 0.0.0+dev.20261006063000, source 8a4e504ae, release head ca650014; activation deployment succeeded.
  • Live two-app/task evidence and a native CLI interactive demo exercised first-bind provisioning, explicit roles, disable/enable and unbind/restart semantics.

The creation-budget and cascade follow-ups are locally verified and not yet deployed; the lab release above remains the earlier baseline.

Rollout and draft dependencies

Companion drafts: cloud_controller_ng #5520, BBS contract #168, Diego #1216, CLI #3875. UAA baseline: cloudfoundry/uaa#4076.

Provision a dedicated management client and correct root trust anchor before enabling provisioning. The lab UAA needed clients.read, clients.write and clients.admin; namespace-restricted provisioning is still an upstream requirement. Use the application root CA when validating Diego leaf+intermediate chains.

Keep runtime gates off until all participating BBS/rep/cells support the typed account contract and enabled cell identity gate; automatic capability negotiation is not implemented. UAA currently emits cnf rather than the draft's bearer-without-cnf profile; feedback is tracked at cloudfoundry/uaa#4076 (review).

Accounts are intentionally space-owned/same-space-only in this revised proposal. This release wiring does not imply immediate credential revocation or complete RFC acceptance. The source pointer is to the companion draft branch and must be aligned with the eventual upstream merge revision.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant