agent: user auth APIs accept and verify request capability, and add user prefix authorization API #2133
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
User authorization APIs can now escalate the capability of a signed token if the user has sufficient privilege. This can be used for administrative actions like journal splitting.
Also add a new prefix authorization API which signs an authorization token valid for a requested and authorized prefix and capability, directed at a specific data-plane.
Add a new, advanced flowctl subcommand for authorizing and printing environment variables for direct gazette access of an authorized prefix.
Workflow steps:
Use
flowctl
to obtain a temporary authorization to an entire (authorized) prefix:Then use it with gazctl or flowctl-go corresponding Gazette PR:
Example of a prefix which is not allowed at the requested capability:
Documentation links affected:
(list any documentation links that you created, or existing ones that you've identified as needing updates, along with a brief description)
Notes for reviewers:
(anything that might help someone review this PR)
This change is