Skip to content

Draft: add native space-owned service-account commands - #3875

Draft
rkoster wants to merge 12 commits into
cloudfoundry:mainfrom
rkoster:service-accounts-poc
Draft

rkoster wants to merge 12 commits into
cloudfoundry:mainfrom
rkoster:service-accounts-poc

Conversation

@rkoster

@rkoster rkoster commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Description of the Change

Community RFC draft: cloudfoundry/community#1645.

Draft native CF CLI support for the service-account proposal, targeting developing v9 (main). The current proposal revision uses immutable space ownership and same-space app assignment rather than org ownership/cross-space grants.

Commands:

  • service-accounts and service-account NAME
  • create-service-account NAME [--description DESCRIPTION]
  • delete-service-account NAME [-f]
  • enable-service-account NAME / disable-service-account NAME
  • bind-service-account APP NAME / unbind-service-account APP

Add typed resources/CAPI methods, owning-space name resolution, pagination, accumulated API warnings, asynchronous job completion and error propagation. Delete defaults to confirmation; -f skips only the prompt. Bind/unbind require explicit app restart and grant no roles. Output exposes platform-returned identity/status and accurately describes residual token/certificate validity. All commands appear in default/full/individual help.

Why Is This PR Valuable?

Operators and app developers can use native commands to manage a shared workload identity without app-distributed secrets. This makes the CAPI/Diego/UAA lab flow reproducible and exposes the lifecycle/restart contract through the intended user interface.

Verification

Separate committed RED/GREEN cycles were used for creation, listing, help and API/actor/command lifecycle behavior. Full affected suites passed:

go test ./resources ./api/cloudcontroller/ccv3 ./actor/v7action ./command/v7 ./command/common/...
go vet ./resources ./api/cloudcontroller/ccv3 ./actor/v7action ./command/v7 ./command/common/...
go test ./api/cloudcontroller/ccv3 ./actor/v7action ./command/v7 ./command/common/... -race -ginkgo.focus='Service Account|service account help discovery|service-accounts|create-service-account|test help all display'

Build/parser/help checks passed. Interface fakes were regenerated with repository-pinned Counterfeiter 6.14.0; its added helper methods explain the large generated-file diff, and repeat generation is stable.

Live validation used go run ./main.go for every CF operation: pushed two apps stopped, created/bound/started a shared account, compared SANs/independent keys, obtained roleless tokens (zero visible apps), granted SpaceAuditor with existing set-space-role --client, disabled/re-enabled, unbound before/after restart and rebound. Disposable create/bind/unbind/disable/enable/delete was also verified.

Applicable Issues and Dependencies

Companion drafts: cloud_controller_ng #5520, capi-release #702, BBS contract #168, Diego #1216. The CAPI API is unreleased; no minimum API version has been invented, and unsupported foundations return CAPI errors. Feature/version discovery, dedicated account-role UX and maintainer API/command naming agreement remain draft criteria.

UAA baseline: cloudfoundry/uaa#4076. Its current cnf token profile differs from the source proposal; tracked feedback: cloudfoundry/uaa#4076 (review). Binding/disable commands do not claim immediate cryptographic revocation.

How Urgent Is The Change?

Not urgent; this is an RFC implementation/discussion draft, not ready-to-merge standard API support.

Other Relevant Parties

CAPI, Diego, UAA and CLI maintainers. Tested head: cd3109f9d. The interactive demo is currently in a separate non-Git lab workspace, not included in this repository diff.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant