Service Accounts
Applies to CoCoCo platform v1.0.0-rc.31. Every step below was run on that version.
A service account is an identity for a machine — an integration, a script, a webhook. It has its own policies and its own API tokens, separate from any person. Why that matters is explained in Service Identities for Integrations.
Before you start: you need the permission to see and create accounts (user:list, user:write), to assign policies (iam:attachPolicy) and to issue tokens (apitoken:write). Taking a policy away, revoking a token and deleting the account need iam:detachPolicy, apitoken:revoke and user:delete. The policy the account should get must already exist — see How to Create an IAM Policy.
Create a service account
Section titled “Create a service account”- In the sidebar, under Identity & Access, click Service accounts.
- Click Add service account. The page New service account opens.
- Enter an Email that says what the account is for, for example
shipping-webhook@example.com. Name is optional. - Click Save in the top right corner. The message Service account created appears and the account’s page opens.
A new service account can do nothing until it has a policy.
Give it a policy
Section titled “Give it a policy”- Under Policies, tick the policy the account should have. The card is marked Assigned and the counter shows (unsaved).
- Click Save in the top right corner. The message Service account updated appears. Nothing is changed before you save.
To take a policy away, untick it and click Save again.
Issue an API token
Section titled “Issue an API token”- Under API Tokens, enter a Token name. Expiration (optional) can stay empty — the token then stays valid until you revoke it.
- Click Create token. The box New token created shows the token. It is shown only once: copy it now and store it where the integration keeps its secrets.
The token acts as the service account: it can do exactly what the account’s policies allow, and nothing else.
Revoke a token
Section titled “Revoke a token”- On the account’s page, under API Tokens, click Revoke next to the token.
- Confirm Revoke this API token? This action cannot be undone. with Revoke.
The token is marked Revoked and is refused from then on.
Delete a service account
Section titled “Delete a service account”- In the list Service accounts, click Delete next to the account (in a short list, a bin icon).
- Confirm Delete service account? with Delete.