Skip to main content

Custom API Roles

Currently with the metrics exporter, a root admin API key is required. This poses a huge security risk for our company by needing to place this sort of key in the hands of a service that really only needs minimal read access. It would be great if a custom role could be defined or an admin read-only role could be created by Spacelift that would allow us to use a role with reduced permissions just for reading metrics and exporting to DD.

Status: ✅ Completed2 comments

Log in to comment and vote

Comments2

  • Black Breeze

    •

    Jun 9, 2025

    FYI this is coming within the next few weeks.

  • Tomato Oak

    •

    Jan 16, 2025

    In order to publish a terraform provider from a CICD system, you’d have to generate an API key and give it admin privileges. However I'd like to restrict that API key to just being able to push things into the terraform/module registry. In order for a provider to then be shared with the entire organization, docs describe putting that into the root space... this isn't ideal, because then the API key would essentially have root access to everything.

    Need a way to either restrict what the API key has permissions to doing, or a way to isolate that API key to a space that doesn’t have access to our AWS integrations. Then sharing that isolated space that contains our providers/modules with the rest of the organization.