Ability to create limited scope tokens with spacectl

Add a way, ideally with the spacectl CLI, to create a (renewable?) access token with more restricted permission scope than the user’s full access.My use case is I would like to use spacectl with AI in a sandbox, so it can view the plans made by PRs, and trigger speculative plans. However, I have more elevated spacelift permissions, and I DO NOT want the AI to be able to make actions that I have access to with my spacelift permissions

Workaround
I can create an organization API key with the relevant permissions. However, this either requires creating a key for every user with elevated permissions, and managing that key separately from the user itself (see also https://feedback.spacelift.io/p/user-based-api-keys), or sharing the secret with multiple users.
Problem
My use case is I would like to use spacectl with AI in a sandbox, so it can view the plans made by PRs, and trigger speculative plans. However, I have more elevated spacelift permissions, and I DO NOT want the AI to be able to make actions that I have access to with my spacelift permissions like modifying or deleting stacks or spaces, confirming plans, etc.

Please authenticate to join the conversation.

Upvoters
Status

👀 In Review

Board

💡 Feature Requests

Tags

Access Control

Date

About 1 hour ago

Subscribe to post

Get notified by email when there are changes.