Repository navigation
Conversation
This was referenced Oct 6, 2026
Draft
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of the Change
Community RFC draft: cloudfoundry/community#1645.
Draft native CF CLI support for the service-account proposal, targeting developing v9 (
main). The current proposal revision uses immutable space ownership and same-space app assignment rather than org ownership/cross-space grants.Commands:
service-accountsandservice-account NAMEcreate-service-account NAME [--description DESCRIPTION]delete-service-account NAME [-f]enable-service-account NAME/disable-service-account NAMEbind-service-account APP NAME/unbind-service-account APPAdd typed resources/CAPI methods, owning-space name resolution, pagination, accumulated API warnings, asynchronous job completion and error propagation. Delete defaults to confirmation;
-fskips only the prompt. Bind/unbind require explicit app restart and grant no roles. Output exposes platform-returned identity/status and accurately describes residual token/certificate validity. All commands appear in default/full/individual help.Why Is This PR Valuable?
Operators and app developers can use native commands to manage a shared workload identity without app-distributed secrets. This makes the CAPI/Diego/UAA lab flow reproducible and exposes the lifecycle/restart contract through the intended user interface.
Verification
Separate committed RED/GREEN cycles were used for creation, listing, help and API/actor/command lifecycle behavior. Full affected suites passed:
Build/parser/help checks passed. Interface fakes were regenerated with repository-pinned Counterfeiter 6.14.0; its added helper methods explain the large generated-file diff, and repeat generation is stable.
Live validation used
go run ./main.gofor every CF operation: pushed two apps stopped, created/bound/started a shared account, compared SANs/independent keys, obtained roleless tokens (zero visible apps), grantedSpaceAuditorwith existingset-space-role --client, disabled/re-enabled, unbound before/after restart and rebound. Disposable create/bind/unbind/disable/enable/delete was also verified.Applicable Issues and Dependencies
Companion drafts: cloud_controller_ng #5520, capi-release #702, BBS contract #168, Diego #1216. The CAPI API is unreleased; no minimum API version has been invented, and unsupported foundations return CAPI errors. Feature/version discovery, dedicated account-role UX and maintainer API/command naming agreement remain draft criteria.
UAA baseline: cloudfoundry/uaa#4076. Its current
cnftoken profile differs from the source proposal; tracked feedback: cloudfoundry/uaa#4076 (review). Binding/disable commands do not claim immediate cryptographic revocation.How Urgent Is The Change?
Not urgent; this is an RFC implementation/discussion draft, not ready-to-merge standard API support.
Other Relevant Parties
CAPI, Diego, UAA and CLI maintainers. Tested head:
cd3109f9d. The interactive demo is currently in a separate non-Git lab workspace, not included in this repository diff.