Skip to main content

Allow adding space hierarchy in OIDC subject

Request: Have a option in Spacelift to enable full space hierarchy in the space claim in the OIDC subject.e.g.

Default. behavior: space:<space_id>:<rest of the claims>

Proposed feature enabled: space:root→space1_id→space1_child_id:<rest of the claims>

Workaround
Problem
Status: ✅ Completed9 comments

This request was merged into another request

Comments9

  • Black Breeze

    •

    May 14, 2025

    Hey! I am going to merge this with other tickets that talk about customizing either OIDC `sub` or custom claims. I personally think this work has a great return on investment, I just need to make sure we implement the right thing the right way, and we don’t miss any security aspects.

    One of my main questions here is - at which level is the OIDC token customized. The safest bet I can think of is account (perhaps in security settings), but is it granular enough?

  • Black Breeze

    •

    May 10, 2025

    Thanks for the suggestion! We looked into this, but it’s not something Spacelift can do directly. When authenticating to AWS via OIDC, Spacelift issues a valid identity token. It’s up to the consumer of that token (typically the Terraform AWS provider or other IaC tool) to include STS session tags when assuming a role.

    If you need session tags—for example, to improve auditability or control—you’ll want to configure them within your Terraform provider or authentication logic. We’ll look at ways to clarify this in our docs.

    • Azure Chipmunk

      •

      May 12, 2025

      Ah, understood. I thought they would have to be set in your backend. Admittedly, I am not particularly familiar with IAM session tags.

      I’ll investigate setting those on our side.

  • Black Breeze

    •

    May 7, 2025

    I 100% see your point. Changing an existing claim would not be backwards-compatible, though. Would there be any downside to making this a separate claim, to not break anyone’s token existing usage?