Clarity on Agent Access Token Scope
- Dominant language
- Ruby
- Stars
- 59
- Forks
- 313
- PR merge metrics
- No merged PRs in 30d
Description
Hey! I was hoping to get some clarity on [Scope of Access](https://buildkite.com/docs/agent/v3/tokens#scope-of-access). In the doc, it describes that an agent access token can be used to register an agent to a queue. What else can it (or the session token) do? Can it
* Arbitrarily set meta-data on any job?
* Arbitrarily upload artifacts to any job?
* Upload additional steps to any job, or just those that are already given to it?
* None of these things?
Thanks!
Contributor guide
Research direction
Start with the linked Scope of Access section in the agent token documentation and review the existing descriptions of agent access and session tokens. Determine the documented permissions for metadata, artifact uploads, and uploading steps, then update the documentation so each of the four questions has an explicit answer.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100