Skip to content

Roles and permissions

Every screen page names the permission an action requires and nothing more (D-8) — this is the one page that says which roles hold it, read from the same grant the control plane enforces.

{"permission": "admin", "grantedTo": null, "grantedOnlyByWildcard": true}
Validated against - · api/schema/permission-vocabulary.generated.json

Generated from Permission. Hand edits to this table are overwritten on the next build — change the Go doc comment, or the generator.

Permission Roles
admin (wildcard only — held by admin through *)
admin:manage (wildcard only — held by admin through *)
admin:read (wildcard only — held by admin through *)
audit:read (wildcard only — held by admin through *)
backups:create operator
backups:delete operator
backups:read developer, operator, readonly, support
backups:restore operator
canary:manage operator
canary:read developer, operator, readonly, support
config:read developer, operator, readonly, support
config:write (wildcard only — held by admin through *)
containers:exec operator
containers:logs developer, operator, support
containers:manage operator
containers:read developer, operator, readonly, support
cronjobs:create operator
cronjobs:delete operator
cronjobs:read developer, operator, readonly, support
cronjobs:update operator
dashboards:manage developer, operator
dashboards:read developer, operator, readonly, support
debug:access operator
deployments:create developer
deployments:delete developer
deployments:manage operator
deployments:read developer, operator, readonly, support
deployments:restart operator
deployments:rollback operator
deployments:scale operator
deployments:start (wildcard only — held by admin through *)
deployments:stop (wildcard only — held by admin through *)
deployments:update developer, operator
events:read developer, operator, readonly, support
images:read developer, operator, readonly, support
jobs:create operator
jobs:delete operator
jobs:read developer, operator, readonly, support
jobs:run operator
jobs:update operator
networks:manage operator
networks:read developer, operator, readonly, support
nodes:manage operator
nodes:read developer, operator, readonly, support
reports:manage operator
reports:read developer, operator, readonly, support
scaling:configure operator
scaling:read developer, operator, readonly, support
scanner:manage operator
scanner:read operator, support
scanner:scan operator
scanner:upgrade operator
sre:approve operator
sre:broadcast operator
sre:configure operator
sre:read developer, operator, readonly, support
sre:trigger operator
vault:manage developer
vault:read developer
volumes:manage operator
volumes:read developer, operator, readonly, support