Skip to content

Manage Product Objects

Use the console for human management after guided setup. Keep work inside the active ordinary zone.

application + provider + resource + active policy → authorized access
AreaOperator task
ApplicationsRegister managed application identities and rotate or reveal client secrets.
ProvidersConfigure the upstream credential mode and rotate provider secrets.
ResourcesDefine resource:// identifiers, operations/scopes, upstream URLs, Gateway application bindings, and provider bindings.
PoliciesAuthor and validate policy versions.
Policy SetsCompose, simulate, and activate the policy that STS evaluates.
Services → LauncherCreate workload identities and launch bindings.
Services → ControlEnable scoped remote automation and manage Control credentials.

Follow Author Policy Data and Activate a Policy Set for the canonical policy workflow rather than duplicating it here.

Application and workload secrets are sealed after creation. A reveal action retrieves the current value from Secret Store custody and writes an admin-audit record. A rotation invalidates the previous value. Copy the replacement directly into the consuming secret store; do not place it in source, screenshots, chat, or audit annotations.

Provider secret fields remain masked and are accepted only by the supported credential create or rotation flow.

Use the Admin SDK for trusted direct management clients. Use Services → Control when remote automation needs a zone-bound credential and the optional Control endpoint is enabled.

Control credentials are scoped to management nouns and verbs. Control calls are replay-protected, rate-limited, and audited. They do not receive the root admin token. Control is not a top-level caracal command and does not manage stack lifecycle.

See Automate Management for dependency and failure implications, and Use the Admin API for endpoint reference.

The reserved system-zone viewer is read-only. It exists to expose Caracal-owned state for transparency, not as a management target. Return to an ordinary selected zone before creating, editing, revealing, rotating, deciding, or deleting anything.

Manage Runtime Authority for Subjects, Authority records, Sessions, Delegations, and Approvals.