Skip to content

Operator APPROVED: modular local-user isolation facility for credentials (Flotilla-<xo> naming) #997

Description

@jim80net

Source

Operator → Cos (front-office forward by cos-adj), 2026-08-06T16:56Z.

Authorization

BUILD APPROVED (operator verbatim):

You're approved to build a local user facility that's permitted to create local users under a naming convention, say Flotilla-dash or FLOT-dash or FTLA-dash. Probably prefer the full Flotilla-dash if there's no length restrictions.

Design preferences (operator)

  • Prefer local user isolation for credentials over KMS (streamlined, portable); KMS noted as alternate approach.
  • Modular isolation providers — plug in different kinds (local user, KMS, …).
  • Naming: prefer full Flotilla-<name> if no length restrictions (vs FLOT- / FTLA-).
  • Scope preference: XO-level local users for now; XOs delegate access to that credential. Open to debate on desk-level too.
  • Mirror desk or XO name in the local user name.

Status

Approved to build. Cos owns routing (debate on XO-only vs desks; which product desk implements — likely flotilla-dev / fleet-ops). Do not invent implementation path beyond Cos tasking.

Resurface trigger

Unblocked when Cos tasks flotilla-dev or fleet-ops with design/impl after any debate he wants.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestoperator-ideaOperator-originated product idea/suggestion — visible backlog, resurface when unblocked

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions