AAC Docs

Using Control Plane

Hosted AAC Control Plane · developer betaMarkdownDocs 42797a46037e

The AAC Control Plane is the shared API service that connects tenant administration, identity, public trust and execution queries. The developer beta provides it as a hosted service. Your CLI, trust anchor publisher and sidecars connect to its endpoints from your own environment.

Your tenant operates its agents and their sidecars, holds its private signing material, and decides what business work to authorize. AAC operates the shared Control Plane and public-trust endpoints.

What it provides

Service How your tenant uses it
Tenant administration Register a tenant and manage its identity-provider connection, credentials and trust domains through the AAC CLI
Security Token Service (STS) Exchange supported identity evidence for short-lived tokens scoped to the intended AAC service
Workload and trust-domain registry Register agent identities, use an AAC-assigned trust domain or bind a domain you control
Public-trust distribution Accept signed publisher uploads and serve tenant root public keys and SPIFFE CA bundles
Execution metadata and audit queries Receive opted-in central telemetry and answer authorized chain listing/trace queries

Business requests travel between agents and sidecars. Local sidecar verification uses trust material it has obtained and cached; the Control Plane does not re-authorize each delegation by contacting all earlier agents. See the overview for the guarantees and limits.

Connect to the developer-beta service

AAC supplies an API endpoint and a public-trust endpoint. For the stage environment used by the AAC journey:

Purpose Endpoint
CLI administration, data APIs, STS and signed trust ingest https://api.stage.cascadeauth.dev
Public root keys and SPIFFE trust bundles https://trust.stage.cascadeauth.dev

Install AAC CLI from PyPI, then create a local profile for those endpoints:

aac profile create stage \
  --admin-url https://api.stage.cascadeauth.dev \
  --data-plane-url https://api.stage.cascadeauth.dev
aac profile show stage --output json

Creating a profile records local connection settings. Continue with tenant registration and sign-in, or use your existing tenant and approved administrator identity. If the stage profile already exists, inspect it before changing it. Other AAC environments supply their own endpoint addresses.

Which component authenticates each request

Keep the credential roles distinct. The keys and certificates guide explains which component holds each one, and the CLI guide covers rotation and recovery.

Check service and tenant state

Check API reachability, then use your authenticated profile to inspect the tenant:

curl --fail --silent --show-error https://api.stage.cascadeauth.dev/healthz
aac tenant list-workloads --profile stage --output table
aac trust-anchor list --profile stage --output table

A successful health response establishes service reachability. Tenant queries and an authenticated agent workflow establish that your particular setup works.

Find an execution

With central telemetry enabled and observations available to your tenant:

aac chain list --profile stage --since 24h --output table
aeg list --profile stage --since 24h --output table

The Control Plane exposes authorized execution metadata. Tenant-local files can add richer authority and application details; they are not uploaded just because you open a graph. Use the AEG guide to combine sources, select a root and understand partial coverage.

Use the CLI command reference for the released administration and query interface, and operations for diagnostics.