Roles and permissions
Every screen page names the permission an action requires and nothing more (D-8) — this is the one page that says which roles hold it, read from the same grant the control plane enforces.
{"permission": "admin", "grantedTo": null, "grantedOnlyByWildcard": true}- · api/schema/permission-vocabulary.generated.jsonGenerated from Permission. Hand edits to this table are overwritten on the next build — change the Go doc comment, or the generator.
| Permission | Roles |
|---|---|
admin |
(wildcard only — held by admin through *) |
admin:manage |
(wildcard only — held by admin through *) |
admin:read |
(wildcard only — held by admin through *) |
audit:read |
(wildcard only — held by admin through *) |
backups:create |
operator |
backups:delete |
operator |
backups:read |
developer, operator, readonly, support |
backups:restore |
operator |
canary:manage |
operator |
canary:read |
developer, operator, readonly, support |
config:read |
developer, operator, readonly, support |
config:write |
(wildcard only — held by admin through *) |
containers:exec |
operator |
containers:logs |
developer, operator, support |
containers:manage |
operator |
containers:read |
developer, operator, readonly, support |
cronjobs:create |
operator |
cronjobs:delete |
operator |
cronjobs:read |
developer, operator, readonly, support |
cronjobs:update |
operator |
dashboards:manage |
developer, operator |
dashboards:read |
developer, operator, readonly, support |
debug:access |
operator |
deployments:create |
developer |
deployments:delete |
developer |
deployments:manage |
operator |
deployments:read |
developer, operator, readonly, support |
deployments:restart |
operator |
deployments:rollback |
operator |
deployments:scale |
operator |
deployments:start |
(wildcard only — held by admin through *) |
deployments:stop |
(wildcard only — held by admin through *) |
deployments:update |
developer, operator |
events:read |
developer, operator, readonly, support |
images:read |
developer, operator, readonly, support |
jobs:create |
operator |
jobs:delete |
operator |
jobs:read |
developer, operator, readonly, support |
jobs:run |
operator |
jobs:update |
operator |
networks:manage |
operator |
networks:read |
developer, operator, readonly, support |
nodes:manage |
operator |
nodes:read |
developer, operator, readonly, support |
reports:manage |
operator |
reports:read |
developer, operator, readonly, support |
scaling:configure |
operator |
scaling:read |
developer, operator, readonly, support |
scanner:manage |
operator |
scanner:read |
operator, support |
scanner:scan |
operator |
scanner:upgrade |
operator |
sre:approve |
operator |
sre:broadcast |
operator |
sre:configure |
operator |
sre:read |
developer, operator, readonly, support |
sre:trigger |
operator |
vault:manage |
developer |
vault:read |
developer |
volumes:manage |
operator |
volumes:read |
developer, operator, readonly, support |