Skip to main content
All access to Anaconda Platform is centrally authenticated and authorized. Human users authenticate through your SSO system. External systems that do not correspond to a human user, such as a CI/CD pipeline, authenticate as machine users. A machine user is a service account: a platform managed identity that authenticates with credentials issued by an external provider, such as GitHub Actions, CircleCI, GitLab, or AWS IAM, instead of a person’s SSO login. Like human users, machine users receive per-perimeter privileges, so you control exactly what each automated system can do. For more information, see What is a user? and Roles and privileges. Admin only

Creating a machine user

  1. Select Users in the left-hand navigation, then select the Machines tab.
  2. Click Create New.
  3. Select the machine user type that matches the system you are connecting, then enter a Name and Description.
  4. Enter the claim values for the selected type, as described in the sections below.
  5. Click Submit.
After you create the machine user, click it in the list to view a generated sample configuration for that type, such as a GitHub Actions workflow or a CircleCI config, that shows how to authenticate as the machine user and trigger flows.

Choosing an identity provider

For OIDC-based types, the Attributes to validate section of the form lists the claims from the provider’s OIDC token that the platform validates during authentication. A machine user can only be used by jobs whose token claims match the values you enter. The available claims depend on the system you are connecting. Select your provider for details:
GitHub Actions jobs authenticate as machine users with OIDC tokens (JWTs) issued by GitHub. A job requests a token and uses it to authenticate to the platform to run, deploy, and trigger flows.The form asks for the claims that appear in GitHub’s OIDC token:
  • Organization: The GitHub organization that owns the repository.
  • Repository: The repository that runs the jobs.
  • Branch: Optional. If set, only jobs triggered from this branch can use the machine user.
  • Environment: Optional. If set, only jobs running within this environment can use the machine user.
  • Workflow: Optional. If set, only jobs running with this workflow name can use the machine user.
The generated sample workflow shown after creation includes the token request and authentication commands.

Using a machine user

After you create a machine user, open it from the list on the Machines tab and select a machine user from the list. The page shows an example configuration specific to that machine user, such as a GitHub Actions workflow or a GitLab CI configuration, that you can copy into your repository and adapt to your use case. The example handles installation and configuration of the outerbounds package for the CI/CD workflow environment, authenticating as the machine user with the credential for its type. For example, GitHub Actions machine users authenticate with GitHub’s OIDC token, and GitLab machine users authenticate with GitLab’s OIDC token. Once configured, the CI/CD environment can run Metaflow flows, access artifacts, and deploy workflows programmatically as the machine user, within the privileges you granted.