Skip to content

Seed InternalUser account + Internal Service Accounts team

Summary

Phase 2 of the Tentacle install-script bootstrap-key redesign. Depends on PR #334 (Phase 1). Base branch set to `feat/system-service-account-role` so merging happens in order.

`InternalUserSeeder` (Order=350) ensures:

  • `user_account` row id=8888 exists (raw SQL INSERT — EF rejects explicit Id for sequence-default columns)
  • "Internal Service Accounts" team exists in space 0 with warning description
  • `SystemServiceAccount` role assigned to team with `SpaceId=null` (cross-space)
  • InternalUser is a team member

End-to-end integration test `SeedRuns_InternalUserHasMachineCreatePermission_ViaAuthorizationService` walks the full `IAuthorizationService.CheckPermissionAsync` path — if this passes, register calls carrying InternalUser-owned API keys will pass MachineCreate.

Least-privilege test `SeedRuns_InternalUserDoesNotHaveMachineDelete` guards against role widening.

Test plan

  • Unit: 5230/5230 pass
  • Integration: 8 new tests pin DB-level invariants (user row, team, role assignment, membership, permission resolution end-to-end, idempotence, seeder ordering)
  • Build: zero errors

🤖 Generated with Claude Code

Merge request reports

Loading