Skip to content

Disallow running Agents using system user#753

Merged
szykol merged 1 commit intodevelopfrom
skolton/system-tokens
Apr 29, 2026
Merged

Disallow running Agents using system user#753
szykol merged 1 commit intodevelopfrom
skolton/system-tokens

Conversation

@szykol
Copy link
Copy Markdown
Collaborator

@szykol szykol commented Apr 29, 2026

Running agents with system user (splunk-system-user) should not be allowed - such user has permissions to do anything within splunk. Giving this capability to Agent should result in an error being thrown.

Developers should not pass Service objects that use the system tokens to the Agent.

@szykol szykol force-pushed the skolton/system-tokens branch 2 times, most recently from 5c7216a to 0fdd2d4 Compare April 29, 2026 07:55
Comment thread splunklib/ai/utils.py Outdated
@szykol szykol force-pushed the skolton/system-tokens branch 2 times, most recently from ab92641 to c0cc8cd Compare April 29, 2026 11:27
@szykol szykol marked this pull request as ready for review April 29, 2026 11:27
Comment thread splunklib/ai/security.py Outdated
Comment thread splunklib/ai/security.py Outdated
Comment thread tests/unit/ai/test_security.py Outdated
@szykol szykol force-pushed the skolton/system-tokens branch from c0cc8cd to 3d4caee Compare April 29, 2026 12:12
@szykol szykol force-pushed the skolton/system-tokens branch from 3d4caee to 83092ce Compare April 29, 2026 12:14
Copy link
Copy Markdown
Member

@mateusz834 mateusz834 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚀

@szykol szykol merged commit d0197f8 into develop Apr 29, 2026
5 of 7 checks passed
@szykol szykol deleted the skolton/system-tokens branch April 29, 2026 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants