oxidecomputer / omicron

Omicron: Oxide control plane
Mozilla Public License 2.0
251 stars 40 forks source link

Service account support #5861

Open askfongjojo opened 5 months ago

askfongjojo commented 5 months ago

The support for service accounts was mentioned originally in #849 but didn't make it to the MVP IAM implementation. The need has come up again based on recent internal/external user requests.

There are a few aspects that distinguish service accounts from regular user accounts:

There are probably more to the service account requirements and will need to be further defined/scoped when this feature is being implemented.

askfongjojo commented 3 months ago

@davepacheco pointed us to these RFDs which describe standard-enough ideas that they might still be accurate/relevant: