Repository navigation
Conversation
This was referenced Oct 6, 2026
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Community RFC draft: cloudfoundry/community#1645.
Draft runtime implementation of the service-account proposal, paired with CAPI-managed space-owned accounts and same-space assignment.
certificate_properties.service_account.namethrough BBS LRP/task conversion into executor.<name>.svc.identityDNS SAN to instance and C2C credentials while preserving caller GUID/CN/IP/OUs, existing routes, usages, lifetime and independent keys.diego.executor.service_account_identity_enabledfor Linux and Windows rep jobs.Backward compatibility
Experimental opt-in; existing account-free workloads preserve their credential shape. SAN-producing inputs in the reserved
svc.identitynamespace are rejected even without an account. Review this namespace restriction as an intentional compatibility change.Keep the CAPI runtime gate off until every participating BBS/rep/cell supports the contract. Automatic auction/foundation capability negotiation is not implemented, so old components discarding unknown protobuf fields remain a rollout risk. Windows templates/cross-compilation were verified; Windows execution was not.
Verification
History preserves committed RED/GREEN behavior cycles.
go test ./executor/... ./rep/...passed, including 62 rep integration and 294 containerstore examples.Contract and other draft dependencies
Merge blocker:
code.cloudfoundry.org/bbs/modelscurrently pins source869b0650f4147bb24d790f52153ef571fc11bda0asv1.15.1-0.20261005213824-869b0650f414. The source is now published in BBS draft #168, but this module version still requires upstream publication/alignment. Vendor was populated from authoritative regenerated protobuf source viago mod vendor; no generated/vendor files were hand-edited. Vendored builds work; fresh module resolution remains a dependency. The stored-LRPAddRunInfofix is part of that dependency.Companion drafts: cloud_controller_ng #5520, capi-release #702, CLI #3875. UAA baseline: cloudfoundry/uaa#4076. Live tokens include
cnf, an explicit deviation from the proposal's bearer profile. Near-expiry lifetime caps, namespace-limited UAA management, timed live renewal and the remaining acceptance matrix are still open.Disabling/unbinding is not immediate certificate revocation. Account authorization/provisioning and staging exclusion are CAPI responsibilities; route-policy integration is subsequent work. Tested release/source head:
307376c4e.