AAC Docs

aac tenant bind-trust-domain

AAC CLI 0.2.8MarkdownDocs 6b7d8268ba78

Bind a SPIFFE trust domain using current exact-name evidence or ceremony.

Synopsis

aac tenant bind-trust-domain
  [-h]
  [--profile PROFILE]
  [--admin-url ADMIN_URL]
  [--data-plane-url DATA_PLANE_URL]
  [--output {json,table}]
  [--tenant-id TENANT_ID]
  --trust-domain TRUST_DOMAIN
  [--bootstrap-token BOOTSTRAP_TOKEN]

Arguments

Argument Type Required Default Description
-h, --help flag no — show this help message and exit
--profile value no — Profile to run under (selection: --profile > AAC_PROFILE > reserved baseline main). aac profile list shows what exists.
--admin-url value no — Admin-surface base URL (overrides profile).
--data-plane-url value no — Data-plane-surface base URL (overrides profile).
--output json | table no json Output mode: json (the default) or table.
--tenant-id value no — Anchor tenant (defaults to the profile/AAC_TENANT_ID identity).
--trust-domain value yes — Canonical trust domain in authority form (e.g. acme.com).
--bootstrap-token value no — Privileged ceremony bootstrap token. Falls back to $AAC_BOOTSTRAP_TOKEN; without one the cached tenant session uses exact current domain evidence for self-service admission.

Output

--output json (the default) prints one JSON document to standard output; --output table prints a readable table instead. Progress notes and diagnostics go to standard error, so the JSON stays parseable.

Exit codes

Code Meaning
0 Success.
1 The control plane or the identity provider rejected the request.
2 Usage error: an invalid flag, value or flag combination.
3 A local configuration or state problem: profile, credential file, cached session or agent.
4 Transport failure: an endpoint could not be reached.

Notes

Creates a distinct, audited binding EPISODE anchored at your tenant. A tenant-admin session may claim a never-bound DNS trust domain only when this tenant owns current domain-verification evidence for the exact same name; the server lazily revalidates evidence when due. Domain verification never creates the binding. If evidence is missing, this command prints the separate issue, verify, and safe-rerun steps. SPIFFE-valid names outside the DNS proof grammar remain ceremony-only via --bootstrap-token. Own-active retries are idempotent. A domain whose latest binding belongs to another tenant cannot be re-bound self-service: moving it is a platform-operated transfer ceremony.