Using Control Plane
The AAC Control Plane is the shared API service that connects tenant administration, identity, public trust and execution queries. The developer beta provides it as a hosted service. Your CLI, trust anchor publisher and sidecars connect to its endpoints from your own environment.
Your tenant operates its agents and their sidecars, holds its private signing material, and decides what business work to authorize. AAC operates the shared Control Plane and public-trust endpoints.
What it provides
| Service | How your tenant uses it |
|---|---|
| Tenant administration | Register a tenant and manage its identity-provider connection, credentials and trust domains through the AAC CLI |
| Security Token Service (STS) | Exchange supported identity evidence for short-lived tokens scoped to the intended AAC service |
| Workload and trust-domain registry | Register agent identities, use an AAC-assigned trust domain or bind a domain you control |
| Public-trust distribution | Accept signed publisher uploads and serve tenant root public keys and SPIFFE CA bundles |
| Execution metadata and audit queries | Receive opted-in central telemetry and answer authorized chain listing/trace queries |
Business requests travel between agents and sidecars. Local sidecar verification uses trust material it has obtained and cached; the Control Plane does not re-authorize each delegation by contacting all earlier agents. See the overview for the guarantees and limits.
Connect to the developer-beta service
AAC supplies an API endpoint and a public-trust endpoint. For the stage environment used by the AAC journey:
| Purpose | Endpoint |
|---|---|
| CLI administration, data APIs, STS and signed trust ingest | https://api.stage.cascadeauth.dev |
| Public root keys and SPIFFE trust bundles | https://trust.stage.cascadeauth.dev |
Install AAC CLI from PyPI, then create a local profile for those endpoints:
aac profile create stage \
--admin-url https://api.stage.cascadeauth.dev \
--data-plane-url https://api.stage.cascadeauth.dev
aac profile show stage --output json
Creating a profile records local connection settings. Continue with
tenant registration and sign-in, or use your
existing tenant and approved administrator identity. If the stage profile
already exists, inspect it before changing it. Other AAC environments supply
their own endpoint addresses.
Which component authenticates each request
- AAC CLI: performs supported registration and administrator sign-in flows, then uses the resulting credentials for tenant operations.
- Trust anchor publisher: signs public-material uploads with the tenant's registered administration key. Configure the publisher.
- Sidecar: uses the configured credentials for services such as workload lookup and central telemetry; the telemetry path exchanges its API-key evidence through STS before ingestion. Configure a sidecar.
- Trust readers: fetch public root keys and CA bundles from the public-trust endpoint. Private keys are retained by the tenant's components.
Keep the credential roles distinct. The keys and certificates guide explains which component holds each one, and the CLI guide covers rotation and recovery.
Check service and tenant state
Check API reachability, then use your authenticated profile to inspect the tenant:
curl --fail --silent --show-error https://api.stage.cascadeauth.dev/healthz
aac tenant list-workloads --profile stage --output table
aac trust-anchor list --profile stage --output table
A successful health response establishes service reachability. Tenant queries and an authenticated agent workflow establish that your particular setup works.
Find an execution
With central telemetry enabled and observations available to your tenant:
aac chain list --profile stage --since 24h --output table
aeg list --profile stage --since 24h --output table
The Control Plane exposes authorized execution metadata. Tenant-local files can add richer authority and application details; they are not uploaded just because you open a graph. Use the AEG guide to combine sources, select a root and understand partial coverage.
Use the CLI command reference for the released administration and query interface, and operations for diagnostics.