Skip to main content
POST
Create Sidecar Service Account

Body

application/json

The request body resource

audience
string
required

The aud the tokens must carry: the control plane URL the sidecar uses. An issuer and audience pair belongs to one organization

Example:

"https://hoop.example.com"

claim
enum<string>
required

The claim matched against subject_pattern

  • sub - The subject, for a Kubernetes service account
  • email - The email, for a Google service account. The token must carry email_verified true
Available options:
sub,
email
Example:

"sub"

issuer
string
required

The exact iss of the tokens. An https URL, where the control plane fetches the keys through OIDC discovery, unless jwks is set

Example:

"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu"

name
string
required

A label for this mapping, unique in the organization

Example:

"gke-eu"

name_template
string
required

The name of the sidecar a matching token reaches. {1} is the text the * matched. A sidecar that exists with this name is used when it is bound to the same identity, or to none (see adopt_existing_sidecars)

Example:

"gke-eu-{1}"

subject_pattern
string
required

An exact value, or one with a single * that matches one or more characters. A bare * needs allow_any_subject. For the issuer https://accounts.google.com it must end in a literal @.iam.gserviceaccount.com

Example:

"system:serviceaccount:*:hoop-sidecar"

adopt_existing_sidecars
boolean

Lets a matching token reach a sidecar an admin created with a token, that no identity is bound to yet, and binds it. The sidecar's token keeps working. Without it the token is refused there

Example:

false

allow_any_subject
boolean

Allows the bare * pattern, which admits every subject of the issuer

Example:

false

jwks
object

A static JWKS for an issuer the control plane cannot reach. Omitted means OIDC discovery at {issuer}/.well-known/openid-configuration

Response

Created

audience
string
required

The aud the tokens must carry: the control plane URL the sidecar uses. An issuer and audience pair belongs to one organization

Example:

"https://hoop.example.com"

claim
enum<string>
required

The claim matched against subject_pattern

  • sub - The subject, for a Kubernetes service account
  • email - The email, for a Google service account. The token must carry email_verified true
Available options:
sub,
email
Example:

"sub"

issuer
string
required

The exact iss of the tokens. An https URL, where the control plane fetches the keys through OIDC discovery, unless jwks is set

Example:

"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu"

name
string
required

A label for this mapping, unique in the organization

Example:

"gke-eu"

name_template
string
required

The name of the sidecar a matching token reaches. {1} is the text the * matched. A sidecar that exists with this name is used when it is bound to the same identity, or to none (see adopt_existing_sidecars)

Example:

"gke-eu-{1}"

subject_pattern
string
required

An exact value, or one with a single * that matches one or more characters. A bare * needs allow_any_subject. For the issuer https://accounts.google.com it must end in a literal @.iam.gserviceaccount.com

Example:

"system:serviceaccount:*:hoop-sidecar"

adopt_existing_sidecars
boolean

Lets a matching token reach a sidecar an admin created with a token, that no identity is bound to yet, and binds it. The sidecar's token keeps working. Without it the token is refused there

Example:

false

allow_any_subject
boolean

Allows the bare * pattern, which admits every subject of the issuer

Example:

false

created_at
string
read-only

Creation timestamp

created_by
string
read-only

The admin who created this mapping

id
string<uuid>
read-only

The unique identifier of this resource

jwks
object

A static JWKS for an issuer the control plane cannot reach. Omitted means OIDC discovery at {issuer}/.well-known/openid-configuration

org_id
string<uuid>
read-only

Organization ID

updated_at
string
read-only

Last update timestamp