Docs

Tokens

Every request to your manager carries a bearer token. The manager stores only a hash of each token; the value is shown once, when it's created.

PrefixWho holds itWhat it can do
ax_admin_You and your CIEverything
ax_dg_A customer's installRegister deployments in one deployment group, pull its chart and images
ax_deploy_One deployment's OperatorSync, report status and telemetry, pull images, hold its tunnel connection
ax_tunnel_Your backendCall deployment tunnels, and nothing else

Admin key

The manager creates an admin key on first start and prints it once. To supply your own, for example from a secret store, set ALIEN_ADMIN_TOKEN to a value starting with ax_admin_; the manager registers it on start. The Helm chart and the ECS module do this for you.

Use it with the CLI:

alien login --manager https://manager.example.com --token ax_admin_...

Customer tokens

alien onboard creates a deployment group and its ax_dg_ token, which goes into the customer's helm install. When the Operator starts, it exchanges that token for an ax_deploy_ token scoped to its own deployment and uses that from then on.

Tunnel tokens

Give your backend a tunnel token rather than an admin key:

alien tokens create --tunnel
alien tokens create --tunnel --customer acme   # only acme's deployments

A tunnel token can call tunnels and nothing else: it can't list deployments or releases, or read logs.

List and revoke

alien tokens ls
alien tokens revoke <id>

Revocation takes effect on the next request.

On this page