Proto changes for bound keypair for agents (#64234)

* Proto changes for bound keypair for agents

This adds the necessary proto changes to support bound keypair for
agents. It just adds a new bound_host_id field (mutually exclusive
with bot_instance_id) and contains no other functional changes.

* Update generated tf docs and schema

* Tweak docstring for bound_key_id
This commit is contained in:
Tim Buckley
2026-03-06 02:05:17 +00:00
committed by GitHub
parent dce0027b08
commit 85e46df86d
5 changed files with 2318 additions and 2218 deletions
@@ -2234,6 +2234,11 @@ message ProvisionTokenStatusV2BoundKeypair {
(gogoproto.nullable) = true,
(gogoproto.jsontag) = "last_rotated_at,omitempty"
];
// BoundHostID is the agent UUID bound to this keypair. This field is left
// empty if bound to a bot, or if no agent has joined yet. It is mutually
// exclusive with BoundBotInstanceID but otherwise behaves identically.
string BoundHostID = 7 [(gogoproto.jsontag) = "bound_host_id"];
}
// StaticTokensV2 implements the StaticTokens interface.
+2267 -2218
View File
File diff suppressed because it is too large Load Diff
@@ -395,6 +395,7 @@ Optional:
Optional:
- `bound_bot_instance_id` (String) BoundBotInstanceID is the ID of the currently associated bot instance. A new bot instance is issued on each join; the new bot instance will have a `previous_bot_instance` set to this value, if any.
- `bound_host_id` (String) BoundHostID is the agent UUID bound to this keypair. This field is left empty if bound to a bot, or if no agent has joined yet. It is mutually exclusive with BoundBotInstanceID but otherwise behaves identically.
- `bound_public_key` (String) BoundPublicKey contains the currently bound public key. If `.spec.bound_keypair.onboarding.initial_public_key` is set, that value will be copied here on creation, otherwise it will be populated as part of public key registration process. This value will be updated over time if keypair rotation takes place, and will always reflect the currently trusted public key. This value is written in SSH authorized_keys format.
- `last_recovered_at` (String) LastRecoveredAt contains a timestamp of the last successful recovery attempt. Note that normal renewals with valid client certificates do not count as a recovery attempt, however the initial join during onboarding does. This corresponds with the last time `bound_bot_instance_id` was updated.
- `last_rotated_at` (String) LastRotatedAt contains a timestamp of the last time the keypair was rotated, if any. This is not set at initial join.
@@ -431,6 +431,7 @@ Optional:
Optional:
- `bound_bot_instance_id` (String) BoundBotInstanceID is the ID of the currently associated bot instance. A new bot instance is issued on each join; the new bot instance will have a `previous_bot_instance` set to this value, if any.
- `bound_host_id` (String) BoundHostID is the agent UUID bound to this keypair. This field is left empty if bound to a bot, or if no agent has joined yet. It is mutually exclusive with BoundBotInstanceID but otherwise behaves identically.
- `bound_public_key` (String) BoundPublicKey contains the currently bound public key. If `.spec.bound_keypair.onboarding.initial_public_key` is set, that value will be copied here on creation, otherwise it will be populated as part of public key registration process. This value will be updated over time if keypair rotation takes place, and will always reflect the currently trusted public key. This value is written in SSH authorized_keys format.
- `last_recovered_at` (String) LastRecoveredAt contains a timestamp of the last successful recovery attempt. Note that normal renewals with valid client certificates do not count as a recovery attempt, however the initial join during onboarding does. This corresponds with the last time `bound_bot_instance_id` was updated.
- `last_rotated_at` (String) LastRotatedAt contains a timestamp of the last time the keypair was rotated, if any. This is not set at initial join.
@@ -1949,6 +1949,11 @@ func GenSchemaProvisionTokenV2(ctx context.Context) (github_com_hashicorp_terraf
Optional: true,
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"bound_host_id": {
Description: "BoundHostID is the agent UUID bound to this keypair. This field is left empty if bound to a bot, or if no agent has joined yet. It is mutually exclusive with BoundBotInstanceID but otherwise behaves identically.",
Optional: true,
Type: github_com_hashicorp_terraform_plugin_framework_types.StringType,
},
"bound_public_key": {
Description: "BoundPublicKey contains the currently bound public key. If `.spec.bound_keypair.onboarding.initial_public_key` is set, that value will be copied here on creation, otherwise it will be populated as part of public key registration process. This value will be updated over time if keypair rotation takes place, and will always reflect the currently trusted public key. This value is written in SSH authorized_keys format.",
Optional: true,
@@ -17894,6 +17899,23 @@ func CopyProvisionTokenV2FromTerraform(_ context.Context, tf github_com_hashicor
}
}
}
{
a, ok := tf.Attrs["bound_host_id"]
if !ok {
diags.Append(attrReadMissingDiag{"ProvisionTokenV2.Status.BoundKeypair.BoundHostID"})
} else {
v, ok := a.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrReadConversionFailureDiag{"ProvisionTokenV2.Status.BoundKeypair.BoundHostID", "github.com/hashicorp/terraform-plugin-framework/types.String"})
} else {
var t string
if !v.Null && !v.Unknown {
t = string(v.Value)
}
obj.BoundHostID = t
}
}
}
}
}
}
@@ -22452,6 +22474,28 @@ func CopyProvisionTokenV2ToTerraform(ctx context.Context, obj *github_com_gravit
tf.Attrs["last_rotated_at"] = v
}
}
{
t, ok := tf.AttrTypes["bound_host_id"]
if !ok {
diags.Append(attrWriteMissingDiag{"ProvisionTokenV2.Status.BoundKeypair.BoundHostID"})
} else {
v, ok := tf.Attrs["bound_host_id"].(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
i, err := t.ValueFromTerraform(ctx, github_com_hashicorp_terraform_plugin_go_tftypes.NewValue(t.TerraformType(ctx), nil))
if err != nil {
diags.Append(attrWriteGeneralError{"ProvisionTokenV2.Status.BoundKeypair.BoundHostID", err})
}
v, ok = i.(github_com_hashicorp_terraform_plugin_framework_types.String)
if !ok {
diags.Append(attrWriteConversionFailureDiag{"ProvisionTokenV2.Status.BoundKeypair.BoundHostID", "github.com/hashicorp/terraform-plugin-framework/types.String"})
}
v.Null = string(obj.BoundHostID) == ""
}
v.Value = string(obj.BoundHostID)
v.Unknown = false
tf.Attrs["bound_host_id"] = v
}
}
}
v.Unknown = false
tf.Attrs["bound_keypair"] = v