Creating a machine user
- Select Users in the left-hand navigation, then select the Machines tab.
- Click Create New.
- Select the machine user type that matches the system you are connecting, then enter a Name and Description.
- Enter the claim values for the selected type, as described in the sections below.
- Click Submit.
Choosing an identity provider
For OIDC-based types, the Attributes to validate section of the form lists the claims from the provider’s OIDC token that the platform validates during authentication. A machine user can only be used by jobs whose token claims match the values you enter. The available claims depend on the system you are connecting. Select your provider for details:- GitHub Actions
- CircleCI
- GitLab
- AWS IAM
- Static API Key
- Azure DevOps
GitHub Actions jobs authenticate as machine users with OIDC tokens (JWTs) issued by GitHub. A job requests a token and uses it to authenticate to the platform to run, deploy, and trigger flows.The form asks for the claims that appear in GitHub’s OIDC token:
- Organization: The GitHub organization that owns the repository.
- Repository: The repository that runs the jobs.
- Branch: Optional. If set, only jobs triggered from this branch can use the machine user.
- Environment: Optional. If set, only jobs running within this environment can use the machine user.
- Workflow: Optional. If set, only jobs running with this workflow name can use the machine user.
Using a machine user
After you create a machine user, open it from the list on the Machines tab and select a machine user from the list. The page shows an example configuration specific to that machine user, such as a GitHub Actions workflow or a GitLab CI configuration, that you can copy into your repository and adapt to your use case. The example handles installation and configuration of theouterbounds package for the CI/CD workflow environment, authenticating as the machine user with the credential for its type. For example, GitHub Actions machine users authenticate with GitHub’s OIDC token, and GitLab machine users authenticate with GitLab’s OIDC token.
Once configured, the CI/CD environment can run Metaflow flows, access artifacts, and deploy workflows programmatically as the machine user, within the privileges you granted.