Add agent API key scope to restrict access to user data#391
Merged
ThomasK33 merged 1 commit intoMay 15, 2025
Conversation
There was a problem hiding this comment.
Pull Request Overview
This pull request adds an "api_key_scope" parameter to the coder agent resource, enabling administrators to restrict agent token access to sensitive routes.
- Added a new "api_key_scope" field with validation in the provider schema.
- Integrated comprehensive tests for valid and invalid parameter values.
- Updated documentation examples to include the new parameter.
Reviewed Changes
Copilot reviewed 5 out of 8 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| provider/agent_test.go | Added tests for valid transitions and error handling for the new "api_key_scope". |
| provider/agent.go | Updated the schema for coder_agent with the new "api_key_scope" field and validation. |
| docs/resources/agent.md | Updated documentation to demonstrate the usage of the new "api_key_scope" parameter. |
Files not reviewed (3)
- .envrc: Language not supported
- examples/resources/coder_agent/resource.tf: Language not supported
- flake.nix: Language not supported
9861bbd to
fa0fe79
Compare
Emyrk
approved these changes
May 8, 2025
Change-Id: I90dd87756b47b589bf0a363e22de70d2cffd44fa Signed-off-by: Thomas Kosiewski <tk@coder.com>
fa0fe79 to
bcd6a7c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Part of coder/coder#17649
Add API Key Scope Control for Coder Agents
This PR introduces a new
api_key_scopeparameter for thecoder_agentresource, allowing administrators to control what API routes an agent token can access. This feature enhances security by providing the option to restrict sensitive user data access.The new parameter supports two options:
all: Full API access (this is the default value)no_user_data: Blocks access to/external-auth,/gitsshkey, and/gitauthroutesChanges:
api_key_scopefield to the agent resource schema with validationDevelopment Environment:
This change is backward compatible as the default behavior remains unchanged.