Context
Working through the bucket-exposure skill workflow (creating a BigQuery Analytics
Hub listing on a Keboola bucket — see #777 for the related create-listing/get-listing
gap). Listing creation on a bucket is a bucket-administrative operation that requires
canManageBuckets on the acting token, scoped to that bucket.
What exists today
kbagent token create only exposes:
--bucket-write <bucket> (write)
--bucket-read <bucket> (read)
There's no way to mint a token with the "manage" permission tier on a specific bucket.
Evidence the API already supports it
kbagent token list on one of our projects shows existing tokens (not minted via
kbagent) with:
"canManageBuckets": true,
"bucketPermissions": {
"out.c-SomeBucket": "manage",
"in.c-OtherBucket": "read"
}
So the Storage API's token-creation endpoint already accepts a per-bucket "manage"
permission level — token create just doesn't expose it as a CLI flag.
Ask
Add a --bucket-manage <bucket> (repeatable) flag to kbagent token create,
mirroring the existing --bucket-write / --bucket-read pattern, so a scoped
token can be minted for bucket-administrative operations (sharing, listings, etc.)
without reaching for the full project master token.
Why this matters
Without it, any workflow needing bucket-manage-level access (e.g. creating an
Analytics Hub listing, per #777) has no least-privilege token option — the only
way to get canManageBuckets today is to hand a full master token to whatever
process needs it, which is a much larger blast radius than the operation requires.
Context
Working through the
bucket-exposureskill workflow (creating a BigQuery AnalyticsHub listing on a Keboola bucket — see #777 for the related create-listing/get-listing
gap). Listing creation on a bucket is a bucket-administrative operation that requires
canManageBucketson the acting token, scoped to that bucket.What exists today
kbagent token createonly exposes:There's no way to mint a token with the "manage" permission tier on a specific bucket.
Evidence the API already supports it
kbagent token liston one of our projects shows existing tokens (not minted viakbagent) with:
So the Storage API's token-creation endpoint already accepts a per-bucket "manage"
permission level —
token createjust doesn't expose it as a CLI flag.Ask
Add a
--bucket-manage <bucket>(repeatable) flag tokbagent token create,mirroring the existing
--bucket-write/--bucket-readpattern, so a scopedtoken can be minted for bucket-administrative operations (sharing, listings, etc.)
without reaching for the full project master token.
Why this matters
Without it, any workflow needing bucket-manage-level access (e.g. creating an
Analytics Hub listing, per #777) has no least-privilege token option — the only
way to get
canManageBucketstoday is to hand a full master token to whateverprocess needs it, which is a much larger blast radius than the operation requires.