Skip to content

docs(crd): a shared credential's revocation is shared - #402

Closed
jleni wants to merge 1 commit into
mainfrom
docs/shared-credential-hazard
Closed

jleni wants to merge 1 commit into
mainfrom
docs/shared-credential-hazard

Conversation

@jleni

@jleni jleni commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

CRD doc-comment and the regenerated schema only.

What was missing

template.files said every Sandbox from the pool gets the same files. It did
not say the consequence: anything done inside one Sandbox that invalidates
the credential invalidates it for every lease from that pool.
readOnly does
not prevent it — a revocation or a token rotation takes effect at the issuing
service, not at the file.

Why the credential's shape is the whole question

expiry refresh rotation on use
machine credential (API key, service account) no no no
credential scoped to a person (OAuth login) yes yes commonly

readOnly is exactly right for the first: nothing a workload does reaches the
credential, and the only way to break the pool is to revoke it deliberately.

For the second it is an obstacle rather than a protection. Such a credential
refreshes and cannot persist the result, so every Sandbox refreshes again; and
the failure modes do not look like credential problems —

  • signing out in any one Sandbox ends every lease's access
  • a refresh performed in one Sandbox can invalidate what the next one reads
  • a workload that keeps writable account metadata beside a read-only
    credential can report one identity while authenticating as another

The field now says to mount a machine credential, and that "someone signed
out" is a first-class explanation when every lease loses access at once.

Scope

Documentation only. It describes what the mechanism does, not what any
particular deployment mounts.

Verification

just build-crdgen regenerated charts/kobe/crds/sandboxpools.yaml;
clippy --all-features -D warnings clean.

`template.files` says every Sandbox from the pool gets the same files. It did
not say the consequence: anything done inside one Sandbox that invalidates the
credential invalidates it for the whole pool, and `readOnly` does not prevent
that — a revocation or a token rotation happens at the provider, not at the
file.

The `sandbox` pool has hit this twice, neither time looking like a credential
problem. A `claude logout` in one Sandbox revoked the token for every lease.
A replacement was taken from whoever's keychain had one, and because the
workload's account metadata is writable while the credential is not, boxes
reported one identity while authenticating as another for days.

Both follow from the credential's shape rather than from the mechanism: a
person's OAuth login is scoped to a human, expires, and usually rotates its
refresh token on use. A machine credential — an API key, a service account —
does none of those, which is what makes `readOnly` right rather than an
obstacle.

So the field now names the distinction and says which to prefer, and says that
"somebody logged out" is a first-class explanation for every lease failing at
once.

This is the documentation half of #375. Which credential the `sandbox` pool
should actually serve is a billing decision, not an engineering one, and the
warning that issue asks for at lease hand-out needs the pool threaded into the
lease response — `sandbox_lease_accepted` takes only the pool's name today.
Both stay open.
@jleni jleni closed this Sep 26, 2026
@jleni jleni changed the title docs(crd): a shared credential's revocation is shared too docs(crd): a shared credential's revocation is shared Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant