2.4 KiB
Why
The Cloud deployment currently requires operators to hand-maintain public API, Host, and enrollment bearer tokens in Compose environment variables. Cloud operator accounts now provide the human authentication boundary, while a Host Agent can establish its own durable identity by registering directly with the trusted control plane. Retaining both models makes deployment error-prone and leaves secrets in configuration without serving the intended workflow.
What Changes
- BREAKING Remove configured public, static Host, and enrollment bearer credentials from the Cloud Control Plane configuration and deployment examples.
- Authorize human Cloud API access exclusively through persistent Cloud user
sessions; remove the Console's bearer-token path and user-directory UI.
Interactive
device-cloud-admincommands remain the account provisioning and recovery surface. - Enable a fresh Host Agent to register directly with the trusted Cloud API without a pre-shared enrollment token, then use its persisted, cloud-bound secret for all later Host operations.
- Bake the packaged Console static directory into the production image rather than repeating it in Compose, and remove Compose entries whose values merely duplicate application defaults or have no runtime effect.
- Update deployment documentation and tests to describe and enforce the tokenless production flow.
Capabilities
New Capabilities
cloud-operator-authentication: Cloud operator sign-in, CLI account provisioning, and a token-free Console experience.credentialless-host-bootstrap: Direct Host registration and durable post-registration identity without static deployment credentials.
Modified Capabilities
platform-sdk: Replace configured bearer credentials as the production authorization prerequisite with Cloud user-session authorization.host-agent-protocol: Add unauthenticated first registration while retaining host-bound authentication for every subsequent Host operation.
Impact
Affected areas include the Cloud control configuration and authentication
composition, public and internal Cloud routers, Host Agent configuration and
enrollment client, Console UI, Docker/Compose deployment assets, tests, and
docs/CLOUD_DEPLOYMENT.md. Existing deployments using the removed static token
variables must create an administrator and re-enroll Hosts through the new
flow before upgrading.