Service accounts
View MarkdownA service account is an identity for machines. Every project has one named default, used by code running
inside Nodus for its own calls. Create more for CI and automation:
nodus create serviceaccount ci -p research --scopes jobs:write,volumes:readManaging service accounts needs serviceaccounts:write (Admins and Owners).
Tokens for CI
Section titled “Tokens for CI”nodus create token sa/ci -p research --duration 720hThis prints a key bound to the service account, once. It is valid for 90 days by default and at most one year.
Its permissions are the service account’s scopes, narrowed further by any --scope you pass.
Service account keys do not belong to a person: they keep working when the member who created them leaves the org, and they stop working when the service account is deleted. Use them for the GitHub Action and any shared automation.
Inside Nodus
Section titled “Inside Nodus”Code running in a Job, Sandbox or Agent reaches the API through /run/nodus/api.sock with a short-lived token of
its service account. The token is never in the environment or on disk, and it stops working the moment its run is
stopped or moved.