Tokens
Every request to your manager carries a bearer token. The manager stores only a hash of each token; the value is shown once, when it's created.
| Prefix | Who holds it | What it can do |
|---|---|---|
ax_admin_ | You and your CI | Everything |
ax_dg_ | A customer's install | Register deployments in one deployment group, pull its chart and images |
ax_deploy_ | One deployment's Operator | Sync, report status and telemetry, pull images, hold its tunnel connection |
ax_tunnel_ | Your backend | Call deployment tunnels, and nothing else |
Admin key
The manager creates an admin key on first start and prints it once. To supply your own, for example from a secret store, set ALIEN_ADMIN_TOKEN to a value starting with ax_admin_; the manager registers it on start. The Helm chart and the ECS module do this for you.
Use it with the CLI:
alien login --manager https://manager.example.com --token ax_admin_...Customer tokens
alien onboard creates a deployment group and its ax_dg_ token, which goes into the customer's helm install. When the Operator starts, it exchanges that token for an ax_deploy_ token scoped to its own deployment and uses that from then on.
Tunnel tokens
Give your backend a tunnel token rather than an admin key:
alien tokens create --tunnel
alien tokens create --tunnel --customer acme # only acme's deploymentsA tunnel token can call tunnels and nothing else: it can't list deployments or releases, or read logs.
List and revoke
alien tokens ls
alien tokens revoke <id>Revocation takes effect on the next request.