Skip to content

Draft: propagate and issue service-account certificate identities - #1216

Draft
rkoster wants to merge 27 commits into
cloudfoundry:developfrom
rkoster:service-accounts-poc
Draft

rkoster wants to merge 27 commits into
cloudfoundry:developfrom
rkoster:service-accounts-poc

Conversation

@rkoster

@rkoster rkoster commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
  • Read the contributing document.

Summary

Community RFC draft: cloudfoundry/community#1645.

Draft runtime implementation of the service-account proposal, paired with CAPI-managed space-owned accounts and same-space assignment.

  • Carry optional typed certificate_properties.service_account.name through BBS LRP/task conversion into executor.
  • Add one canonical <name>.svc.identity DNS SAN to instance and C2C credentials while preserving caller GUID/CN/IP/OUs, existing routes, usages, lifetime and independent keys.
  • Retain launch-time account identity on timed renewal/route-triggered regeneration; copy account pointers when copying container snapshots.
  • Validate canonical names and reserve the account SAN namespace across internal-route and instance-GUID inputs, including case/trailing-dot variants.
  • Fail closed when account credentials are requested without identity support or an enabled gate. Declare/render default-off diego.executor.service_account_identity_enabled for Linux and Windows rep jobs.
  • Document operator rollout and contract provenance.

Backward compatibility

Experimental opt-in; existing account-free workloads preserve their credential shape. SAN-producing inputs in the reserved svc.identity namespace are rejected even without an account. Review this namespace restriction as an intentional compatibility change.

Keep the CAPI runtime gate off until every participating BBS/rep/cell supports the contract. Automatic auction/foundation capability negotiation is not implemented, so old components discarding unknown protobuf fields remain a rollout risk. Windows templates/cross-compilation were verified; Windows execution was not.

Verification

History preserves committed RED/GREEN behavior cycles.

  • Full go test ./executor/... ./rep/... passed, including 62 rep integration and 294 containerstore examples.
  • 137 release-template examples passed; focused race tests, go vet and formatting checks passed.
  • Linux rep/gocurl/BBS builds and Windows rep cross-build passed.
  • Wire → stored-LRP assembly → rep → real certificate tests cover shared identity across two apps/task, independent keys, renewal and unbind invariants.
  • Live lab: two apps and a runtime task received the shared SAN; app keys differ; UAA token acquisition and explicit CAPI role access succeeded; unbind retains running identity until restart, restart removes it, rebind restores it.

Contract and other draft dependencies

Merge blocker: code.cloudfoundry.org/bbs/models currently pins source 869b0650f4147bb24d790f52153ef571fc11bda0 as v1.15.1-0.20261005213824-869b0650f414. The source is now published in BBS draft #168, but this module version still requires upstream publication/alignment. Vendor was populated from authoritative regenerated protobuf source via go mod vendor; no generated/vendor files were hand-edited. Vendored builds work; fresh module resolution remains a dependency. The stored-LRP AddRunInfo fix is part of that dependency.

Companion drafts: cloud_controller_ng #5520, capi-release #702, CLI #3875. UAA baseline: cloudfoundry/uaa#4076. Live tokens include cnf, an explicit deviation from the proposal's bearer profile. Near-expiry lifetime caps, namespace-limited UAA management, timed live renewal and the remaining acceptance matrix are still open.

Disabling/unbinding is not immediate certificate revocation. Account authorization/provisioning and staging exclusion are CAPI responsibilities; route-policy integration is subsequent work. Tested release/source head: 307376c4e.

rkoster added 27 commits October 5, 2026 17:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

1 participant