Skip to content

Add SystemServiceAccount built-in role for bootstrap operations

Placeholder ppxd requested to merge feat/system-service-account-role into main

Summary

Phase 1 of the Tentacle install-script bootstrap-key redesign. Adds a new built-in role `SystemServiceAccount` for the internal account that will own the shared bootstrap API key.

Permissions: `MachineView` + `MachineCreate` + `MachineEdit` only. Deliberately omits `MachineDelete` (bootstrap must not delete machines) + all deployment / account / environment / task permissions.

`BuiltInRoleDefinition` gains `IsReservedForSystem` (default false; true on the new role). `PermissionRoleResolver.GetBuiltInRolesGranting` filters reserved roles by default so operator-facing 403 hints never suggest assigning a system-reserved role to a human. An `includeSystemReserved: true` overload exposes the full list for seeders / diagnostics.

Test plan

  • Unit: 5230/5230 pass (6 new SystemServiceAccount-specific tests + filter-behavior pin)
  • Build: zero errors
  • Integration: Phase 2 will land the InternalUser seeder that consumes this role; integration test belongs there

Phase 2-5 of the series will land in follow-up PRs.

🤖 Generated with Claude Code

Merge request reports

Loading