Super administrative stacks
Currently a stack can be administrative, which means that can create resources for its space and child spaces. However, there’s no way to create resources for parent or sibling spaces.
Among other possibilities, this is useful to create contexts to other spaces (parents/siblings) in a programmatic way, while protecting some sensitive contexts from inheritance.
Use case:
‘root’ space has 2 childs (‘users’ and ‘admins’). ‘root’ space contains shared resources for both of them (shared credentials, TF modules, admin stacks, etc).
‘admin‘ space contains a context with org-admin credentials, which can NOT be shared to ‘users‘ space for security reasons. Since both childs inherit from ‘root‘, the org-admin credentials’ context can NOT be on ‘root’.
Then, a stack in ‘admin‘ space (by using the org-admin credentials) creates projects with scoped credentials for each of them, and these new credentials are now safe to be shared to and used from ‘users‘ space. To do so, after creating the new credentials, the stack with “super administrative“ privileges creates different contexts in ‘users‘ space for the stacks there to consume them. Alternatively, those different contexts could be created also in `root` space so they would be shared to all.
Log in to comment and vote
Comments4
Sep 17
PinnedThere seems to be already a solution suggested that seems to solve the original problem. Please follow up if this solution isn’t feasible, with more details. Thank you!
Teal Lynx
Aug 24
We have recently done this by adding in a new space as a child of root but as a parent of the other 2 spaces. You can then attach the context update/create permissions to child stacks for the new parent (non root) space and it can create those resources there
Black Breeze
May 8, 2025
This is planned somewhere in Q3. The idea is for stacks to optionally have execution roles, like how a Lambda can have an IAM role in AWS.
Aquamarine Savanna
Apr 1, 2025
This could be useful also to programmatically create dependencies across sibling spaces