Configure CI with the required permissions
Prepare a dedicated service account and a key with permissions for the endpoint groups the job uses. Creating the identity and key requires administrative permission. See the api-keys reference for permissions.
Steps
npm install -g @orchestor-inc/cli@0.5.0
orc --version
orc auth status --json
orc service-accounts create \
--workspace WORKSPACE_ID \
--name "CI bot" \
--scope workspace \
--jsonUse the service-account ID from the response. Grant only the endpoint groups that the job calls. Select a new output file outside source control.
orc service-accounts keys create SERVICE_ACCOUNT_ID \
--workspace WORKSPACE_ID \
--name "CI read key" \
--permissions '{"answers":"read"}' \
--output /secure/path/service-account-key \
--jsonThe CLI does not write the key to standard output or standard error. Register the value from the owner-only output file with your CI secret facility, and then securely delete the file. Inject that secret as ORCHESTOR_API_KEY in the CI job. Replace WORKSPACE_ID with the job target. Do not run browser login or credential-persisting init in the job.
Run the following read from the job. It requires read permission for the answers endpoint group.
orc answers list --workspace WORKSPACE_ID --limit 1 --jsonRecord only the version, target ID, and request outcome. Do not log the key or authorization header. For a 403, inspect the missing permission rather than substituting an administrator key. When the key is no longer needed, restore your management CLI identity and run orc api-keys delete API_KEY_ID --workspace WORKSPACE_ID --yes.
If a failure remains, report it and verify the fix, including this workflow and the failed step.