Skip to content

feat: support Platform API 1.167 features (audit logs, IdP groups, SCIM, Intelligent Compute) - #698

Open
cristianrcv wants to merge 7 commits into
masterfrom
feat/NOTASK-tw-api-1.167
Open

cristianrcv wants to merge 7 commits into
masterfrom
feat/NOTASK-tw-api-1.167

Conversation

@cristianrcv

@cristianrcv cristianrcv commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Exposes features introduced in Platform API 1.167.0: admin audit logs, organization IdP groups and SCIM, linking teams to IdP groups, and the first Intelligent Compute tuning options.

This is one PR in a stack that catches tw up with Platform API 1.230.0: one PR per API version that introduced the features, then one PR per topic for agents and actions, which are grouped across versions so they're easier to review.

Changes

  • feat(compute-envs): add Intelligent Compute options to cloud platforms (388c307)
  • feat(organizations): add IdP group and SCIM commands (7ece82e)
  • feat(teams): link teams to IdP groups (497d1a9)
  • feat(audit-logs): add audit-logs command (24f17fe)
  • fix(audit-logs): delete the downloaded CSV after export (b5e9185)
  • docs: document the commands and options added for API 1.167 (46f67e2)
  • build(native): register reflection metadata for the API 1.167 commands (24a2d7e)

Notes for review

  • Audit logs: --state is only offered on audit-logs export. The SDK (1.200.0 and 1.230.0) cannot deserialize the AuditLogTargetStateNewState oneOf, which ignores its discriminator. export downloads into a temp file, which is always deleted.
  • Intelligent Compute: --prediction-model, --nvme-storage, --backend-strategy and the warm-pool options match the UI. In the Platform code I read, they are stored but not yet acted on.

Verification

  • ./gradlew test: 890 tests, 0 failures. Every new command and option has MockServer tests that assert the request (method, path, query, body) and the output.
  • CI runs the full suite against the native binary on Linux, macOS and Windows.

🤖 Generated with Claude Code

@cristianrcv
cristianrcv added this pull request to stack #704 October 5, 2026 16:12
@cristianrcv
cristianrcv requested review from a team and educalleja October 5, 2026 16:18
@cristianrcv
cristianrcv removed this pull request from stack #704 October 5, 2026 16:20
@cristianrcv
cristianrcv added this pull request to stack #705 October 5, 2026 16:20

@educalleja educalleja left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Usage of the new commands and options

This PR adds three new command groups (tw audit-logs, tw organizations idp-groups and tw organizations scim), IdP group options for tw teams add|update, and new Intelligent Compute (Seqera scheduler) options for tw compute-envs add aws-cloud|azure-cloud|google-cloud.

1. tw audit-logs (new)

"Inspect the installation audit logs." Every subcommand requires a root user (platform administrator). None of them take a workspace or organization option, because the logs cover the whole installation.

tw audit-logs list

Lists audit logs, newest first.

Option Description
--after Show only logs on or after this ISO-8601 date-time, such as 2026-01-31T00:00:00Z
--before Show only logs on or before this ISO-8601 date-time, such as 2026-01-31T23:59:59Z
--max Maximum number of logs per page
--page-token Token of the page to show, as printed by a previous list with the same filters
  • The output is a table with ID, Timestamp, Event, Actor, Target type and Target name.
  • When there are more logs, it prints "More logs available, use: --page-token <token>". Pagination uses this token, not the usual --page / --offset options.

tw audit-logs view

Shows one audit log.

Option Description
-i, --id Audit log ID (required)
  • The output shows ID, Timestamp, Event, Correlation ID, Actor, Actor email, Actor type, Client IP, User agent, Target type, Target ID, Target name, Organization and Workspace. If the log includes the target's state, it's printed as JSON.

tw audit-logs export

Exports audit logs as CSV. It fails when too many logs match, so narrow the date range if that happens.

Option Description
--after / --before Same date-time filters as list
--state Include the state of each target before and after the change. Requires the audit state images feature
-o, --output CSV file to write. Without it, the CSV is printed to stdout
  • With -o, it prints "Audit logs exported to '<file>'".
  • --state is only offered on export (see the PR's review notes).
tw audit-logs export --after 2026-09-01T00:00:00Z --before 2026-09-30T23:59:59Z -o september.csv

2. tw organizations idp-groups (new)

Manages the organization's list of IdP groups, which teams can be linked to. Requires IdP claims mapping to be enabled for the organization. Every subcommand requires -o, --organization (organization name or numeric ID).

Command Description Other options
list Lists IdP groups, both those pushed by SCIM and those added manually. Columns: ID, Name, Source None
add Adds an IdP group manually -n, --name (required): must exactly match the value your IdP sends in the groups claim
delete Deletes a manually added IdP group. Groups pushed by SCIM can't be deleted -i, --id / -n, --name: exactly one is required
  • For delete by name, an unknown name fails with "IdP group '<name>' not found in organization '<orgId>'".

3. tw organizations scim (new)

Manages SCIM provisioning for the organization. Requires IdP claims mapping to be enabled for the organization. Every subcommand takes only -o, --organization (required).

Command Description
view Shows the SCIM configuration and token status: Endpoint URL, SSO active, Active token, Token (masked), Token created, Token last used and Groups (count)
create-token Generates a SCIM bearer token. It revokes the active token, if there is one. The token is shown only once, with the SCIM endpoint URL
rotate-token Revokes the active SCIM bearer token and generates a new one. The token is shown only once
revoke-token Revokes the active SCIM bearer token

4. tw teams add|update: link teams to IdP groups

Command Option Description
add, update --idp-group Link the team to this IdP group, by its name as shown by tw organizations idp-groups list. The IdP then manages team membership
update --unlink-idp-group Remove the IdP group link so team members can be managed manually again
  • On update, --idp-group and --unlink-idp-group can't be used together.
  • tw teams view now shows the team's IdP group.

5. tw compute-envs add: Intelligent Compute options

New options in the "Scheduler options" group, next to the existing --sched-enabled, --provisioning-model and --sched-machine-types.

Option aws-cloud azure-cloud google-cloud Description
--prediction-model ✓ ✓ ✓ Model the scheduler uses to predict task resource requirements. Suggested values: none, qr/v1, qr/v2, qr/v3. If you leave it out, the scheduler default (none) applies
--nvme-storage ✓ ✓ ✓ Only use instance types with local SSD (NVMe) storage, for faster I/O
--backend-strategy ✓ Backend the scheduler runs tasks on: ECS (AWS ECS runs the tasks) or EC2 (tasks run directly on EC2 instances)
--warm-pool ✓ Keep a pool of idle VMs ready to take incoming tasks with minimal start latency. Requires --warm-pool-size. Only applies with --backend-strategy EC2
--warm-pool-size ✓ Number of idle VMs to keep in the warm pool. Must be greater than zero
--warm-pool-scale-to-zero <seconds> ✓ Seconds of inactivity after which the warm pool scales to zero. 0 means it never scales to zero
  • --warm-pool without a --warm-pool-size greater than zero fails with "Option --warm-pool requires --warm-pool-size greater than zero."
  • Per the PR's review notes, --prediction-model, --nvme-storage, --backend-strategy and the warm-pool options are stored by Platform but not yet acted on.

USAGE.md

  • "Teams and quotas" is renamed to "Teams, IdP groups and SCIM", with entries for --idp-group / --unlink-idp-group, tw organizations idp-groups list|add|delete and tw organizations scim view|create-token|rotate-token|revoke-token.
  • A new "Audit logs" section, with the export example above.
  • A bullet for the Intelligent Compute options on aws-cloud, azure-cloud and google-cloud.

🤖 Generated with Claude Code

@cristianrcv
cristianrcv force-pushed the feat/NOTASK-tw-api-1.145 branch from 7074dd0 to 1ae323f Compare October 7, 2026 09:39
@cristianrcv
cristianrcv removed this pull request from stack #705 October 7, 2026 13:26
@cristianrcv
cristianrcv force-pushed the feat/NOTASK-tw-api-1.145 branch from 1ae323f to 24cb0df Compare October 7, 2026 14:50
@cristianrcv
cristianrcv deleted the branch master October 8, 2026 09:09
@cristianrcv cristianrcv closed this Oct 8, 2026
@cristianrcv
cristianrcv deleted the feat/NOTASK-tw-api-1.167 branch October 8, 2026 09:09
@cristianrcv
cristianrcv restored the feat/NOTASK-tw-api-1.167 branch October 8, 2026 09:11
@cristianrcv cristianrcv reopened this Oct 8, 2026
@cristianrcv
cristianrcv changed the base branch from feat/NOTASK-tw-api-1.145 to master October 8, 2026 09:14
Platform API 1.167.0 added SchedConfig fields that tw never set, so
Intelligent Compute CEs created from the CLI could not choose a
prediction model, NVMe/local-SSD instances, or the AWS backend strategy
and warm pool.

Options are added only where Platform accepts them, matching the
tower-web forms and WithSeqeraSchedulerSupport.validateSchedConfig:
- all cloud platforms: --prediction-model, --nvme-storage;
- aws-cloud only: --backend-strategy and the warm pool options
  (--warm-pool, --warm-pool-size, --warm-pool-scale-to-zero).

diskAllocation is not exposed: nvmeEnabled is Platform's boolean view
over it and its only value is 'nvme'.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
cristianrcv and others added 6 commits October 8, 2026 11:16
Platform API 1.167 added the organization IdP group catalog and SCIM
provisioning admin endpoints, which tw did not expose. Without them a
team could not be linked to an IdP group from the CLI, and SCIM tokens
could only be managed in the UI.

Add 'tw organizations idp-groups' (list, add, delete) and
'tw organizations scim' (view, create-token, rotate-token,
revoke-token). Both are gated by the IdP claims mapping feature
(TOWER_IDP_CLAIMS_MAPPING_ENABLED plus an optional org allowlist), which
is on by default in Enterprise and enabled in Seqera Cloud, so the help
text names the requirement instead of calling it enterprise-only.

'idp-groups delete' resolves the group by display name, so the
findIdpGroupByName helper lands here; 'teams --idp-group' reuses it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
API 1.167 added linking a team to an IdP group (idpGroupId on the team
create and update requests, idpGroupName on the team response), but tw
could not set or show it.

'teams add' and 'teams update' accept --idp-group <display name>,
resolved through the organization's IdP group catalog, and
'teams update --unlink-idp-group' clears the link. 'teams view' shows
the linked IdP group.

The update request's idpGroupId is tri-state: omitted keeps the link,
an explicit null removes it, so --unlink-idp-group sends null and an
update without either option leaves the link untouched.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Platform API 1.167.0 added the v2 audit log endpoints (token-paged
list, describe and CSV export) and tw had no way to read them.

tw audit-logs list filters by a date range (--after/--before) and
pages with --max and --page-token; view shows one log; export writes
the CSV to a file (-o) or stdout, optionally with the target state
images (--state). The endpoints are installation-wide and reserved to
root users, which the help says.

view does not offer --state: the SDK (1.200.0 and 1.230.0) cannot
deserialize state images, because its generated oneOf deserializer
ignores the auditImageType discriminator and every image schema
matches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The SDK downloads the export into a temp file. Printing it to stdout left that file behind, and
it holds installation-wide audit data (actor emails, client IPs, state images). Delete it in every
path.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Add the audit-logs section, the organization IdP group and SCIM
commands, the teams IdP group options, and the Intelligent Compute
options of the cloud compute environments. Examples use bash code
blocks without a prompt (markdownlint MD014).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The native binary needs reflection entries for every picocli command,
option group and JSON response class. Add those of the audit-logs,
organizations idp-groups and scim commands and of the teams IdP group
option group, copied from the reflection config generated for the full
catch-up.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants