hydraperforceprovision (and the per-org p4d scales it manages) currently authenticate to Perforce as the human super user hydra_admin. A person's password should not live inside a service. Replace it with a dedicated non-human super service account per p4d instance.
hydra_admin's password in /etc/hydraperforceprovision/config.yaml (mode 600) to create depots/users/protections. If that human's password is rotated, the service breaks; if the service is compromised, the human's credentials leak.ensure-server creates each scale's super as hydra_admin (fleet.super_user). Every org scale should instead get a dedicated super service account.hydraperforceprovision/docs/runbooks/runbook.md (Security notes) and repeated in #484.galloromeinsmuseum on hydraskin-perforce-1, 178.105.185.28): create a dedicated super, e.g. provision_svc, with its own strong password; grant super in the protections table; verify it can create depots/users/protections.hydraperforceprovision config perforce.admin_user/admin_password at provision_svc; restart; re-verify a provision call end to end.fleet.super_user: provision_svc so future ensure-server scales use it (each scale still gets its OWN generated password, stored 0600 in the scale state file).hydra_admin as the break-glass human super (do not delete); document that services use provision_svc, humans use hydra_admin.provision_svc password out of band (not in git); consider moving service secrets to Pantheon with only a handle in config (ties into the #484 state-file-security note).p4 passwd (never -P), and clear the forced-reset flag for the service account by changing its own password (a service can't do an interactive first-login reset).super for depot/protection management, so it is privileged by necessity — the win is decoupling it from a human identity, not reducing its rights.DONE 2026-08-15 on the live Gallo-Romeins scale (galloromeinsmuseum @ hydraskin-perforce-1).
super user provision_svc * //... appended to protections — existing lines/koen/watcher untouched). Cleared the Security-Level-4 forced-reset flag by changing its password as itself so it can log in non-interactively. Verified maxaccess=super and it can run admin commands.Credentials delivered to cederik out of band (provision_svc password NOT in this issue). Rotate via p4 passwd provision_svc as a super.
LICENSE NOTE: two super seats (hydra_admin break-glass + provision_svc) plus the watcher's read hydraperforce_svc = 3 of the free tier's 5 per-server seats, leaving 2 for creators (koen is 1). If Cyborn adds several devs this scale hits the cap -> paid license or consolidation. Documented in the runbook.
Safe to close. Human super login via iamnim SSO remains separate (nimsforest #206).
Related: iamnim OIDC/SAML IdP support requested on the NimsForest tracker as nimsforest #206. That is the enabler for logging into Perforce as an iamnim identity (Helix Authentication Service / auth-check-sso trigger need an OIDC/SAML IdP to point at). This issue (dedicated service account) stands on its own and does not depend on #206 — the service account uses a p4 password regardless; #206 is about HUMAN super login via iamnim SSO.