Repository navigation
feat: support Platform API 1.167 features (audit logs, IdP groups, SCIM, Intelligent Compute) - #698
cristianrcv wants to merge 7 commits into
Conversation
educalleja
left a comment
There was a problem hiding this comment.
Usage of the new commands and options
This PR adds three new command groups (tw audit-logs, tw organizations idp-groups and tw organizations scim), IdP group options for tw teams add|update, and new Intelligent Compute (Seqera scheduler) options for tw compute-envs add aws-cloud|azure-cloud|google-cloud.
1. tw audit-logs (new)
"Inspect the installation audit logs." Every subcommand requires a root user (platform administrator). None of them take a workspace or organization option, because the logs cover the whole installation.
tw audit-logs list
Lists audit logs, newest first.
| Option | Description |
|---|---|
--after |
Show only logs on or after this ISO-8601 date-time, such as 2026-01-31T00:00:00Z |
--before |
Show only logs on or before this ISO-8601 date-time, such as 2026-01-31T23:59:59Z |
--max |
Maximum number of logs per page |
--page-token |
Token of the page to show, as printed by a previous list with the same filters |
- The output is a table with ID, Timestamp, Event, Actor, Target type and Target name.
- When there are more logs, it prints "More logs available, use: --page-token <token>". Pagination uses this token, not the usual
--page/--offsetoptions.
tw audit-logs view
Shows one audit log.
| Option | Description |
|---|---|
-i, --id |
Audit log ID (required) |
- The output shows ID, Timestamp, Event, Correlation ID, Actor, Actor email, Actor type, Client IP, User agent, Target type, Target ID, Target name, Organization and Workspace. If the log includes the target's state, it's printed as JSON.
tw audit-logs export
Exports audit logs as CSV. It fails when too many logs match, so narrow the date range if that happens.
| Option | Description |
|---|---|
--after / --before |
Same date-time filters as list |
--state |
Include the state of each target before and after the change. Requires the audit state images feature |
-o, --output |
CSV file to write. Without it, the CSV is printed to stdout |
- With
-o, it prints "Audit logs exported to '<file>'". --stateis only offered onexport(see the PR's review notes).
tw audit-logs export --after 2026-09-01T00:00:00Z --before 2026-09-30T23:59:59Z -o september.csv2. tw organizations idp-groups (new)
Manages the organization's list of IdP groups, which teams can be linked to. Requires IdP claims mapping to be enabled for the organization. Every subcommand requires -o, --organization (organization name or numeric ID).
| Command | Description | Other options |
|---|---|---|
list |
Lists IdP groups, both those pushed by SCIM and those added manually. Columns: ID, Name, Source | None |
add |
Adds an IdP group manually | -n, --name (required): must exactly match the value your IdP sends in the groups claim |
delete |
Deletes a manually added IdP group. Groups pushed by SCIM can't be deleted | -i, --id / -n, --name: exactly one is required |
- For
deleteby name, an unknown name fails with "IdP group '<name>' not found in organization '<orgId>'".
3. tw organizations scim (new)
Manages SCIM provisioning for the organization. Requires IdP claims mapping to be enabled for the organization. Every subcommand takes only -o, --organization (required).
| Command | Description |
|---|---|
view |
Shows the SCIM configuration and token status: Endpoint URL, SSO active, Active token, Token (masked), Token created, Token last used and Groups (count) |
create-token |
Generates a SCIM bearer token. It revokes the active token, if there is one. The token is shown only once, with the SCIM endpoint URL |
rotate-token |
Revokes the active SCIM bearer token and generates a new one. The token is shown only once |
revoke-token |
Revokes the active SCIM bearer token |
4. tw teams add|update: link teams to IdP groups
| Command | Option | Description |
|---|---|---|
add, update |
--idp-group |
Link the team to this IdP group, by its name as shown by tw organizations idp-groups list. The IdP then manages team membership |
update |
--unlink-idp-group |
Remove the IdP group link so team members can be managed manually again |
- On
update,--idp-groupand--unlink-idp-groupcan't be used together. tw teams viewnow shows the team's IdP group.
5. tw compute-envs add: Intelligent Compute options
New options in the "Scheduler options" group, next to the existing --sched-enabled, --provisioning-model and --sched-machine-types.
| Option | aws-cloud |
azure-cloud |
google-cloud |
Description |
|---|---|---|---|---|
--prediction-model |
✓ | ✓ | ✓ | Model the scheduler uses to predict task resource requirements. Suggested values: none, qr/v1, qr/v2, qr/v3. If you leave it out, the scheduler default (none) applies |
--nvme-storage |
✓ | ✓ | ✓ | Only use instance types with local SSD (NVMe) storage, for faster I/O |
--backend-strategy |
✓ | Backend the scheduler runs tasks on: ECS (AWS ECS runs the tasks) or EC2 (tasks run directly on EC2 instances) |
||
--warm-pool |
✓ | Keep a pool of idle VMs ready to take incoming tasks with minimal start latency. Requires --warm-pool-size. Only applies with --backend-strategy EC2 |
||
--warm-pool-size |
✓ | Number of idle VMs to keep in the warm pool. Must be greater than zero | ||
--warm-pool-scale-to-zero <seconds> |
✓ | Seconds of inactivity after which the warm pool scales to zero. 0 means it never scales to zero |
--warm-poolwithout a--warm-pool-sizegreater than zero fails with "Option --warm-pool requires --warm-pool-size greater than zero."- Per the PR's review notes,
--prediction-model,--nvme-storage,--backend-strategyand the warm-pool options are stored by Platform but not yet acted on.
USAGE.md
- "Teams and quotas" is renamed to "Teams, IdP groups and SCIM", with entries for
--idp-group/--unlink-idp-group,tw organizations idp-groups list|add|deleteandtw organizations scim view|create-token|rotate-token|revoke-token. - A new "Audit logs" section, with the
exportexample above. - A bullet for the Intelligent Compute options on
aws-cloud,azure-cloudandgoogle-cloud.
🤖 Generated with Claude Code
7074dd0 to
1ae323f
Compare
1ae323f to
24cb0df
Compare
Platform API 1.167.0 added SchedConfig fields that tw never set, so Intelligent Compute CEs created from the CLI could not choose a prediction model, NVMe/local-SSD instances, or the AWS backend strategy and warm pool. Options are added only where Platform accepts them, matching the tower-web forms and WithSeqeraSchedulerSupport.validateSchedConfig: - all cloud platforms: --prediction-model, --nvme-storage; - aws-cloud only: --backend-strategy and the warm pool options (--warm-pool, --warm-pool-size, --warm-pool-scale-to-zero). diskAllocation is not exposed: nvmeEnabled is Platform's boolean view over it and its only value is 'nvme'. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Platform API 1.167 added the organization IdP group catalog and SCIM provisioning admin endpoints, which tw did not expose. Without them a team could not be linked to an IdP group from the CLI, and SCIM tokens could only be managed in the UI. Add 'tw organizations idp-groups' (list, add, delete) and 'tw organizations scim' (view, create-token, rotate-token, revoke-token). Both are gated by the IdP claims mapping feature (TOWER_IDP_CLAIMS_MAPPING_ENABLED plus an optional org allowlist), which is on by default in Enterprise and enabled in Seqera Cloud, so the help text names the requirement instead of calling it enterprise-only. 'idp-groups delete' resolves the group by display name, so the findIdpGroupByName helper lands here; 'teams --idp-group' reuses it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
API 1.167 added linking a team to an IdP group (idpGroupId on the team create and update requests, idpGroupName on the team response), but tw could not set or show it. 'teams add' and 'teams update' accept --idp-group <display name>, resolved through the organization's IdP group catalog, and 'teams update --unlink-idp-group' clears the link. 'teams view' shows the linked IdP group. The update request's idpGroupId is tri-state: omitted keeps the link, an explicit null removes it, so --unlink-idp-group sends null and an update without either option leaves the link untouched. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Platform API 1.167.0 added the v2 audit log endpoints (token-paged list, describe and CSV export) and tw had no way to read them. tw audit-logs list filters by a date range (--after/--before) and pages with --max and --page-token; view shows one log; export writes the CSV to a file (-o) or stdout, optionally with the target state images (--state). The endpoints are installation-wide and reserved to root users, which the help says. view does not offer --state: the SDK (1.200.0 and 1.230.0) cannot deserialize state images, because its generated oneOf deserializer ignores the auditImageType discriminator and every image schema matches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The SDK downloads the export into a temp file. Printing it to stdout left that file behind, and it holds installation-wide audit data (actor emails, client IPs, state images). Delete it in every path. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Add the audit-logs section, the organization IdP group and SCIM commands, the teams IdP group options, and the Intelligent Compute options of the cloud compute environments. Examples use bash code blocks without a prompt (markdownlint MD014). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The native binary needs reflection entries for every picocli command, option group and JSON response class. Add those of the audit-logs, organizations idp-groups and scim commands and of the teams IdP group option group, copied from the reflection config generated for the full catch-up. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
24a2d7e to
004ff90
Compare
Summary
Exposes features introduced in Platform API 1.167.0: admin audit logs, organization IdP groups and SCIM, linking teams to IdP groups, and the first Intelligent Compute tuning options.
This is one PR in a stack that catches tw up with Platform API 1.230.0: one PR per API version that introduced the features, then one PR per topic for agents and actions, which are grouped across versions so they're easier to review.
tower-java-sdk1.200.0, which already contains every API element used here. The 1.230 PR bumps it.Changes
Notes for review
--stateis only offered onaudit-logs export. The SDK (1.200.0 and 1.230.0) cannot deserialize theAuditLogTargetStateNewStateoneOf, which ignores its discriminator.exportdownloads into a temp file, which is always deleted.--prediction-model,--nvme-storage,--backend-strategyand the warm-pool options match the UI. In the Platform code I read, they are stored but not yet acted on.Verification
./gradlew test: 890 tests, 0 failures. Every new command and option has MockServer tests that assert the request (method, path, query, body) and the output.🤖 Generated with Claude Code