Skip to main content

Super administrative stacks

Currently a stack can be administrative, which means that can create resources for its space and child spaces. However, there’s no way to create resources for parent or sibling spaces.

Among other possibilities, this is useful to create contexts to other spaces (parents/siblings) in a programmatic way, while protecting some sensitive contexts from inheritance.

Use case:

‘root’ space has 2 childs (‘users’ and ‘admins’). ‘root’ space contains shared resources for both of them (shared credentials, TF modules, admin stacks, etc).

‘admin‘ space contains a context with org-admin credentials, which can NOT be shared to ‘users‘ space for security reasons. Since both childs inherit from ‘root‘, the org-admin credentials’ context can NOT be on ‘root’.

Then, a stack in ‘admin‘ space (by using the org-admin credentials) creates projects with scoped credentials for each of them, and these new credentials are now safe to be shared to and used from ‘users‘ space. To do so, after creating the new credentials, the stack with “super administrative“ privileges creates different contexts in ‘users‘ space for the stacks there to consume them. Alternatively, those different contexts could be created also in `root` space so they would be shared to all.

Status: ⌛ Waiting for User4 comments

Log in to comment and vote

Comments4

  • Ovidiu Moise changed status to ⌛ Waiting for User
    Team•

    Sep 17

    Pinned

    There seems to be already a solution suggested that seems to solve the original problem. Please follow up if this solution isn’t feasible, with more details. Thank you!

  • Teal Lynx

    •

    Aug 24

    We have recently done this by adding in a new space as a child of root but as a parent of the other 2 spaces. You can then attach the context update/create permissions to child stacks for the new parent (non root) space and it can create those resources there

  • Black Breeze

    •

    May 8, 2025

    This is planned somewhere in Q3. The idea is for stacks to optionally have execution roles, like how a Lambda can have an IAM role in AWS.

  • Aquamarine Savanna

    •

    Apr 1, 2025

    This could be useful also to programmatically create dependencies across sibling spaces