Skip to main content

Make spacectl authentication easier

Currently it seems like the 3 options to authenticate to spacectl are either short-lived forms of authentication or not accessible to non-admins:

  • Login with browser gives a temporary API token that expires after 10 hours, and then I have to re-enter my Spacelift URL in the CLI every day. This is not sustainable for a daily workflow.

  • Github PAT seems easier if your IdP is Github, but for me, it signs out my browser session whenever I use spacectl, and re-authing in my browser signs out the CLI. This is again not sustainable for a daily workflow.

  • API keys remove the re-auth problem but are completely separate from my user identity, and it’s not clear that non-admins in Spacelift can create them. This also creates long-lived API credentials, which we’d prefer to avoid.

I would be fine with opening my browser to authenticate every day if I didn’t have to enter the Spacelift URL continually.

Status: 🗑️ Archived3 comments

Log in to comment and vote

Comments3

  • Natalia Gazda

    Team•

    Nov 25, 2024

    Hi @Evan Strat,

    It's already solved by logging in without providing the profile alias.

    spacectl profile login

    When we provide the alias, we go through the process of providing the URL and other auth details.

    ~ $ spacectl profile login prod Enter Spacelift endpoint (eg. https://unicorn.app.spacelift.io/):

    When we don't provide the alias, spacectl reuses an existing profile, and doesn't require to provide the URL.

    ~ $ spacectl profile login Waiting for login responses at 127.0.0.1:56682

    As a side-note, you can use spacectl profile select ALIAS to switch between aliases, and then log in without needing to provide the URL.

    Would that solve your issue? :)

    • Pink Broccoli

      •

      Nov 26, 2024

      Yes, this does seem to work, thanks!

      • Natalia Gazda

        Team•

        Nov 26, 2024

        Great, then I’ll close this on our side :)