curl --request PUT \
--url https://use.hoop.dev/api/sidecar-service-accounts/{id} \
--header 'Content-Type: application/json' \
--data '
{
"audience": "https://hoop.example.com",
"claim": "sub",
"issuer": "https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu",
"name": "gke-eu",
"name_template": "gke-eu-{1}",
"subject_pattern": "system:serviceaccount:*:hoop-sidecar",
"adopt_existing_sidecars": false,
"allow_any_subject": false,
"jwks": {}
}
'import requests
url = "https://use.hoop.dev/api/sidecar-service-accounts/{id}"
payload = {
"audience": "https://hoop.example.com",
"claim": "sub",
"issuer": "https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu",
"name": "gke-eu",
"name_template": "gke-eu-{1}",
"subject_pattern": "system:serviceaccount:*:hoop-sidecar",
"adopt_existing_sidecars": False,
"allow_any_subject": False,
"jwks": {}
}
headers = {"Content-Type": "application/json"}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
audience: 'https://hoop.example.com',
claim: 'sub',
issuer: 'https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu',
name: 'gke-eu',
name_template: 'gke-eu-{1}',
subject_pattern: 'system:serviceaccount:*:hoop-sidecar',
adopt_existing_sidecars: false,
allow_any_subject: false,
jwks: {}
})
};
fetch('https://use.hoop.dev/api/sidecar-service-accounts/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://use.hoop.dev/api/sidecar-service-accounts/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'audience' => 'https://hoop.example.com',
'claim' => 'sub',
'issuer' => 'https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu',
'name' => 'gke-eu',
'name_template' => 'gke-eu-{1}',
'subject_pattern' => 'system:serviceaccount:*:hoop-sidecar',
'adopt_existing_sidecars' => false,
'allow_any_subject' => false,
'jwks' => [
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://use.hoop.dev/api/sidecar-service-accounts/{id}"
payload := strings.NewReader("{\n \"audience\": \"https://hoop.example.com\",\n \"claim\": \"sub\",\n \"issuer\": \"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu\",\n \"name\": \"gke-eu\",\n \"name_template\": \"gke-eu-{1}\",\n \"subject_pattern\": \"system:serviceaccount:*:hoop-sidecar\",\n \"adopt_existing_sidecars\": false,\n \"allow_any_subject\": false,\n \"jwks\": {}\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://use.hoop.dev/api/sidecar-service-accounts/{id}")
.header("Content-Type", "application/json")
.body("{\n \"audience\": \"https://hoop.example.com\",\n \"claim\": \"sub\",\n \"issuer\": \"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu\",\n \"name\": \"gke-eu\",\n \"name_template\": \"gke-eu-{1}\",\n \"subject_pattern\": \"system:serviceaccount:*:hoop-sidecar\",\n \"adopt_existing_sidecars\": false,\n \"allow_any_subject\": false,\n \"jwks\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://use.hoop.dev/api/sidecar-service-accounts/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"audience\": \"https://hoop.example.com\",\n \"claim\": \"sub\",\n \"issuer\": \"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu\",\n \"name\": \"gke-eu\",\n \"name_template\": \"gke-eu-{1}\",\n \"subject_pattern\": \"system:serviceaccount:*:hoop-sidecar\",\n \"adopt_existing_sidecars\": false,\n \"allow_any_subject\": false,\n \"jwks\": {}\n}"
response = http.request(request)
puts response.read_body{
"audience": "https://hoop.example.com",
"claim": "sub",
"issuer": "https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu",
"name": "gke-eu",
"name_template": "gke-eu-{1}",
"subject_pattern": "system:serviceaccount:*:hoop-sidecar",
"adopt_existing_sidecars": false,
"allow_any_subject": false,
"created_at": "<string>",
"created_by": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"jwks": {},
"org_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"updated_at": "<string>"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}Update Sidecar Service Account
Replace a sidecar service account. The sidecars it reached keep their names; a token it no longer matches stops authenticating. 409 when another organization uses the new issuer and audience.
curl --request PUT \
--url https://use.hoop.dev/api/sidecar-service-accounts/{id} \
--header 'Content-Type: application/json' \
--data '
{
"audience": "https://hoop.example.com",
"claim": "sub",
"issuer": "https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu",
"name": "gke-eu",
"name_template": "gke-eu-{1}",
"subject_pattern": "system:serviceaccount:*:hoop-sidecar",
"adopt_existing_sidecars": false,
"allow_any_subject": false,
"jwks": {}
}
'import requests
url = "https://use.hoop.dev/api/sidecar-service-accounts/{id}"
payload = {
"audience": "https://hoop.example.com",
"claim": "sub",
"issuer": "https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu",
"name": "gke-eu",
"name_template": "gke-eu-{1}",
"subject_pattern": "system:serviceaccount:*:hoop-sidecar",
"adopt_existing_sidecars": False,
"allow_any_subject": False,
"jwks": {}
}
headers = {"Content-Type": "application/json"}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
audience: 'https://hoop.example.com',
claim: 'sub',
issuer: 'https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu',
name: 'gke-eu',
name_template: 'gke-eu-{1}',
subject_pattern: 'system:serviceaccount:*:hoop-sidecar',
adopt_existing_sidecars: false,
allow_any_subject: false,
jwks: {}
})
};
fetch('https://use.hoop.dev/api/sidecar-service-accounts/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://use.hoop.dev/api/sidecar-service-accounts/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'audience' => 'https://hoop.example.com',
'claim' => 'sub',
'issuer' => 'https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu',
'name' => 'gke-eu',
'name_template' => 'gke-eu-{1}',
'subject_pattern' => 'system:serviceaccount:*:hoop-sidecar',
'adopt_existing_sidecars' => false,
'allow_any_subject' => false,
'jwks' => [
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://use.hoop.dev/api/sidecar-service-accounts/{id}"
payload := strings.NewReader("{\n \"audience\": \"https://hoop.example.com\",\n \"claim\": \"sub\",\n \"issuer\": \"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu\",\n \"name\": \"gke-eu\",\n \"name_template\": \"gke-eu-{1}\",\n \"subject_pattern\": \"system:serviceaccount:*:hoop-sidecar\",\n \"adopt_existing_sidecars\": false,\n \"allow_any_subject\": false,\n \"jwks\": {}\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://use.hoop.dev/api/sidecar-service-accounts/{id}")
.header("Content-Type", "application/json")
.body("{\n \"audience\": \"https://hoop.example.com\",\n \"claim\": \"sub\",\n \"issuer\": \"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu\",\n \"name\": \"gke-eu\",\n \"name_template\": \"gke-eu-{1}\",\n \"subject_pattern\": \"system:serviceaccount:*:hoop-sidecar\",\n \"adopt_existing_sidecars\": false,\n \"allow_any_subject\": false,\n \"jwks\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://use.hoop.dev/api/sidecar-service-accounts/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"audience\": \"https://hoop.example.com\",\n \"claim\": \"sub\",\n \"issuer\": \"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu\",\n \"name\": \"gke-eu\",\n \"name_template\": \"gke-eu-{1}\",\n \"subject_pattern\": \"system:serviceaccount:*:hoop-sidecar\",\n \"adopt_existing_sidecars\": false,\n \"allow_any_subject\": false,\n \"jwks\": {}\n}"
response = http.request(request)
puts response.read_body{
"audience": "https://hoop.example.com",
"claim": "sub",
"issuer": "https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu",
"name": "gke-eu",
"name_template": "gke-eu-{1}",
"subject_pattern": "system:serviceaccount:*:hoop-sidecar",
"adopt_existing_sidecars": false,
"allow_any_subject": false,
"created_at": "<string>",
"created_by": "<string>",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"jwks": {},
"org_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"updated_at": "<string>"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}Path Parameters
Sidecar service account ID
Body
The request body resource
The aud the tokens must carry: the control plane URL the sidecar uses. An issuer and audience pair belongs to one organization
"https://hoop.example.com"
The claim matched against subject_pattern
- sub - The subject, for a Kubernetes service account
- email - The email, for a Google service account. The token must carry email_verified true
sub, email "sub"
The exact iss of the tokens. An https URL, where the control plane fetches the keys through OIDC discovery, unless jwks is set
"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu"
A label for this mapping, unique in the organization
"gke-eu"
The name of the sidecar a matching token reaches. {1} is the text the * matched. A sidecar that exists with this name is used when it is bound to the same identity, or to none (see adopt_existing_sidecars)
"gke-eu-{1}"
An exact value, or one with a single * that matches one or more characters. A bare * needs allow_any_subject. For the issuer https://accounts.google.com it must end in a literal @.iam.gserviceaccount.com
"system:serviceaccount:*:hoop-sidecar"
Lets a matching token reach a sidecar an admin created with a token, that no identity is bound to yet, and binds it. The sidecar's token keeps working. Without it the token is refused there
false
Allows the bare * pattern, which admits every subject of the issuer
false
A static JWKS for an issuer the control plane cannot reach. Omitted means OIDC discovery at {issuer}/.well-known/openid-configuration
Response
OK
The aud the tokens must carry: the control plane URL the sidecar uses. An issuer and audience pair belongs to one organization
"https://hoop.example.com"
The claim matched against subject_pattern
- sub - The subject, for a Kubernetes service account
- email - The email, for a Google service account. The token must carry email_verified true
sub, email "sub"
The exact iss of the tokens. An https URL, where the control plane fetches the keys through OIDC discovery, unless jwks is set
"https://container.googleapis.com/v1/projects/my-project/locations/europe-west1/clusters/eu"
A label for this mapping, unique in the organization
"gke-eu"
The name of the sidecar a matching token reaches. {1} is the text the * matched. A sidecar that exists with this name is used when it is bound to the same identity, or to none (see adopt_existing_sidecars)
"gke-eu-{1}"
An exact value, or one with a single * that matches one or more characters. A bare * needs allow_any_subject. For the issuer https://accounts.google.com it must end in a literal @.iam.gserviceaccount.com
"system:serviceaccount:*:hoop-sidecar"
Lets a matching token reach a sidecar an admin created with a token, that no identity is bound to yet, and binds it. The sidecar's token keeps working. Without it the token is refused there
false
Allows the bare * pattern, which admits every subject of the issuer
false
Creation timestamp
The admin who created this mapping
The unique identifier of this resource
A static JWKS for an issuer the control plane cannot reach. Omitted means OIDC discovery at {issuer}/.well-known/openid-configuration
Organization ID
Last update timestamp
Was this page helpful?