Partner client
The partner client is your platform’s own client. It authenticates with partner tokens that your platform signs with its private key, and it acts across every tenant your platform owns. Use the partner client to:- Create, list, update, and delete tenants.
- Set a tenant’s policies.
- Issue tenant tokens, which create tenant clients.
partnerTokenSource and create the partner client step by step.
Tenant client
A tenant client acts inside exactly one tenant. Everything it creates belongs to that tenant, and it cannot see or change any other tenant. Use a tenant client to:- Run instances, builds, and other workloads.
- Use storage, such as cache volumes, the container registry, and secrets.
- Read the tenant’s policies.
- Create, list, and revoke revokable tokens.
- From a tenant token
- From your nsc login
In production, your platform acts for a customer with a tenant token.
The partner client issues the token for the customer’s tenant, and the tenant client authenticates with it.The tenant client acts in the tenant the token was issued for.
Tenant tokens covers choosing an actor ID and a duration, defining
bearerTokenSource in Go, and keeping tokens fresh in long-running services.Next steps
Create tenants
Give each of your customers their own tenant.
Authentication
The credentials behind each client.