Project

General

Profile

Actions

Feature #272

open

Epic #49: Implement user, groups and permissions management

Agent identity

Feature #272: Agent identity

Added by Bricklou 9 days ago. Updated 8 days ago.

Status:
Planned
Priority:
Normal
Assigned To:
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
(Total: 0:00 h)

Description

A node that runs game servers must prove it is a node this installation enrolled, and an operator must be able to cut one off when it is decommissioned or compromised. Agents carry out work the control plane hands them; they never judge what a person is allowed to do.

An administrator enrols a node by generating a short-lived, single-use token. The node presents it once, receives its own lasting credential, and uses that from then on. Credentials are listable, can be rotated, and can be revoked one node at a time.


Rejection reason

Superseded by the rewritten epic #49


Subtasks 2 (2 open — 0 closed)

User Story #300: As an administrator, I want to enrol a new node with a one-off token, so that only nodes I invited can joinPlannedBricklou

Actions
User Story #301: As an administrator, I want to list, rotate and revoke node credentials, so that a decommissioned or compromised node loses access immediatelyPlannedBricklou

Actions
Actions

Also available in: PDF Atom