package models import "time" // Service account scopes. Instance acts with the same reach system // administration has over teams: create one, list them, mint a team-scoped // account against any of them. Team acts as that one team's owner, and // nothing else. const ( ServiceAccountScopeInstance = "instance" ServiceAccountScopeTeam = "team" ) // ServiceAccount is a non-human credential: not a users row, so it never // touches OIDC group sync, login, or the is_admin flag, and is never mistaken // for a human in an audit trail (see api_keys' user_id, which every service // account key deliberately does not have). type ServiceAccount struct { ID int64 `json:"id"` Name string `json:"name"` Scope string `json:"scope"` TeamID *int64 `json:"team_id,omitempty"` CreatedBy *int64 `json:"created_by,omitempty"` CreatedAt time.Time `json:"created_at"` } // ServiceAccountKey is one bearer credential on a ServiceAccount. Multiple // keys per account, the same shape as APIKey, are what let rotation mint a // new one and revoke the old without recreating the account. type ServiceAccountKey struct { ID int64 `json:"id"` ServiceAccountID int64 `json:"service_account_id"` Name string `json:"name"` CreatedAt time.Time `json:"created_at"` LastUsedAt *time.Time `json:"last_used_at,omitempty"` Key string `json:"key,omitempty"` // populated only on creation, never stored }