Admiral

Access

Authentication

Sign in to Admiral in the console or the CLI, and use a personal or service account API key, bounded by scopes, for scripts and CI.

Admiral is hosted, so authentication has two sides: how people sign in through the console or the CLI, and how machines (CI and automation) authenticate to the API. This page explains both. There is no identity provider for you to install or configure, because that is part of the managed service.

Signing in

You sign in to the console through your identity, and the CLI signs in the same way:

admiral auth login

admiral auth login opens a browser to complete sign-in, then stores a session so subsequent commands are authenticated. Your session is maintained by Admiral Cloud with configurable idle and absolute lifetimes.

Token types

For anything non-interactive you use an API key. Admiral issues two kinds, for two different access patterns.

Personal API keys

  • Scoped to an individual user.
  • Created in the console.
  • Used for CLI access and API calls on your behalf.
  • Act with your permissions, limited to the scopes the key was created with.

Use a personal API key for local scripting and one-off automation that acts as you. A key stops working when its owner leaves the organization.

Service account API keys

  • Scoped to a service identity, not a person.
  • Created in the console or through the API.
  • Used by machines, such as CI pipelines.
  • Do not vanish when a person leaves.

Use a service account API key for CI. An agent does not use an API key. Admiral trusts its cluster instead, see Agents.

Scopes

API keys carry scopes that bound what they can do (for example, catalog:read versus catalog:write). Grant the narrowest scope that fits the job, especially for a service account key that lives in CI. A personal key for Terraform is limited to the Terraform API, which serves hosted state.

Rotating and revoking

Treat an API key like any other secret. Rotate service account keys on a schedule, and revoke any key that may be exposed. A revoked key stops authenticating immediately.

Where to go next

On this page