Repository navigation
Conversation
This was referenced Oct 6, 2026
Draft
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Community RFC draft: cloudfoundry/community#1645.
Draft implementation of the service-account proposal, exercised end-to-end in a CF lab.
Intentional proposal revision: accounts are space-owned, with one immutable owning space and same-space app assignment only. This supersedes the gist's org ownership/cross-space use grants. Names remain foundation-unique and immutable, with permanent deletion tombstones.
/v3/service_accountscreate/list/show/update/delete and account app listing, plus GET/PATCH/v3/apps/:guid/relationships/service_account.cf:service-account:<name>, exact<name>.svc.identityDNS SAN) and roleless CAPI OAuth principals on first bind through retryable pollable jobs. Reuse active provisioning jobs and reject client/principal collisions and conflicting lifecycle operations.VCAP_SERVICE_ACCOUNT, exclude staging, and reject unsupported/unready runtime identity. Assignment changes require explicit restart.Verification
History intentionally preserves small failing-test RED and passing-implementation GREEN commits.
RFC follow-ups: budget RED
93fffd2bc→ GREENa1a6dc0b5; cascade RED052cd6293/ corrected runtime fixture REDc3c53dfec→ GREENec582b703.Follow-up verification: 38 budget/request examples (including concurrent cross-space creation), 105 lifecycle/action/request regressions, 42 space/org deletion request regressions; all passing. Nine changed Ruby files lint-clean. Creation ledger migration exercised on PostgreSQL.
Local milestone: 721 targeted request/unit examples passed; 57 changed Ruby files lint-clean; API documentation build passed.
Subsequent lab fixes: MySQL migration/assignment regressions (8 examples) and full managed-client provisioning action (15 examples) passed with lint checks.
Live two-app and runtime-task validation: same account SAN, independent keys; certificate-authenticated token acquisition; zero visible apps without roles and two after an explicit role grant; disable blocks new tokens; enable retains roles; unbind without restart retains launch identity, restart removes the SAN and old-account authentication fails.
Native CLI demo completed the flow using
go run ./main.go, including provisioning jobs and lifecycle operations.Draft dependencies and open criteria
cnf; the draft requires bearer issuance without it. Per-client RFC 8705 policy feedback: Harden the RFC 8705 mTLS token endpoint - Supersedes 3792 uaa#4076 (review). CAPI registration will also need explicittls_client_certificate_bound_access_tokens: falseonce UAA honors it.clients.adminin addition to read/write to register CAPI authorities. Namespace-limited client administration is not yet demonstrated; managed account clients receive no management authorities.869b0650f4147bb24d790f52153ef571fc11bda0, now published in BBS draft #168. Generated bindings originate there. Upstream module publication/version alignment remains a merge prerequisite.These follow-ups are locally verified and not yet deployed to the lab. Account-backed OSB bindings and account route grants remain future integration work; cascade currently cleans existing service bindings/workloads and account registrations/principals.
This is a discussion/implementation draft, not a claim of full RFC acceptance. Tested source head:
ec582b703ef80fa9b9c5b3c34ca2798a29b4b801.