Skip to content

feat: token create needs a bucket-manage scope (canManageBuckets per bucket) #779

Description

@vojtechnovotny-heu

Context

Working through the bucket-exposure skill workflow (creating a BigQuery Analytics
Hub listing on a Keboola bucket — see #777 for the related create-listing/get-listing
gap). Listing creation on a bucket is a bucket-administrative operation that requires
canManageBuckets on the acting token, scoped to that bucket.

What exists today

kbagent token create only exposes:

--bucket-write <bucket>   (write)
--bucket-read <bucket>    (read)

There's no way to mint a token with the "manage" permission tier on a specific bucket.

Evidence the API already supports it

kbagent token list on one of our projects shows existing tokens (not minted via
kbagent) with:

"canManageBuckets": true,
"bucketPermissions": {
  "out.c-SomeBucket": "manage",
  "in.c-OtherBucket": "read"
}

So the Storage API's token-creation endpoint already accepts a per-bucket "manage"
permission level — token create just doesn't expose it as a CLI flag.

Ask

Add a --bucket-manage <bucket> (repeatable) flag to kbagent token create,
mirroring the existing --bucket-write / --bucket-read pattern, so a scoped
token can be minted for bucket-administrative operations (sharing, listings, etc.)
without reaching for the full project master token.

Why this matters

Without it, any workflow needing bucket-manage-level access (e.g. creating an
Analytics Hub listing, per #777) has no least-privilege token option — the only
way to get canManageBuckets today is to hand a full master token to whatever
process needs it, which is a much larger blast radius than the operation requires.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions