Skip to content

Service accounts

View Markdown

A service account is an identity for machines. Every project has one named default, used by code running inside Nodus for its own calls. Create more for CI and automation:

Terminal window
nodus create serviceaccount ci -p research --scopes jobs:write,volumes:read

Managing service accounts needs serviceaccounts:write (Admins and Owners).

Terminal window
nodus create token sa/ci -p research --duration 720h

This prints a key bound to the service account, once. It is valid for 90 days by default and at most one year. Its permissions are the service account’s scopes, narrowed further by any --scope you pass.

Service account keys do not belong to a person: they keep working when the member who created them leaves the org, and they stop working when the service account is deleted. Use them for the GitHub Action and any shared automation.

Code running in a Job, Sandbox or Agent reaches the API through /run/nodus/api.sock with a short-lived token of its service account. The token is never in the environment or on disk, and it stops working the moment its run is stopped or moved.