Permissions
The actions that govern apps and slots, what each allows, and the roles that hold them.
Actions
| Action | Allows |
|---|---|
apps/read |
See apps and their slots — including the values of their environment variables and scaling triggers — deployment history, revisions, metrics, certificate status and source; list the runtime stacks and compute plans |
apps/write |
Create apps and slots; change their configuration; deploy, start, stop and restart; redeploy a version; roll back. Includes apps/delete |
apps/delete |
Delete apps and slots |
apps/scale |
Not checked by the portal or the API today: scaling is changed in the app's configuration, which needs apps/write |
apps/readLogs |
Read container logs and build logs; list an app's instances |
apps/readFiles |
Browse and download files on an app's disk |
apps/writeFiles |
Upload, create, rename, move and delete files on an app's disk |
apps/readLogs, apps/readFiles and apps/writeFiles are data actions: a role grants them only
when it lists them as data actions, so managing an app does not by that alone let you read its
logs or its files. Reading logs also needs boundaries/workloads/read and
boundaries/workloads/readLogs, which the platform checks when it reads the app's pods; every role
below that can read logs has them.
Other actions an app's page uses: choosing a repository needs kernel/deployments/read, the
Activity tab needs kernel/activity/read, and the Operations tab needs
kernel/operations/read.
Roles
| Role | Apps | Logs | Files |
|---|---|---|---|
| Reader | See | Read | No |
| Apps Reader | See | No | No |
| Apps Operator | See, create, change, delete | Read | Read and change |
| Contributor, Owner | See, create, change, delete | Read | Read and change |
| Platform Reader | See | No | No |
| Platform Contributor, Platform Owner | See, create, change, delete | Read | Read and change |
Assign a role on a boundary, a resource group or a single app — see Role assignments. A role on an app covers its slots. All built-in roles are described in Built-in roles.
Caution
For anyone who also signs in to a cluster's Kubernetes API server, an assignment on a boundary or a resource group gives more there than in the portal:
- Apps Operator — like Owner, Contributor, Platform Owner and Platform Contributor — carries
pods/exec: a shell in every pod of the namespaces the assignment covers, not only in apps. The file actions reach the disk through it.apps/writeandapps/scalelet the holder change the app's Kubernetes resource directly, the whole resource and without the platform's checks —apps/scaletoo, although the portal and the API do not use it.See Kubernetes RBAC.
What the portal shows
On an app's page the portal hides what you cannot use: the Configuration tab and the
Deploy, Start, Stop, Restart, Redeploy this version and Roll back buttons
without apps/write, the Danger Zone without apps/delete, and the Files tab without
apps/readFiles. On the Slots tab and on a slot's page only Restart, Stop and
Start are hidden: Create Slot, the delete buttons, Deploy, the Configuration tab and
the Danger Zone are shown to everyone who can see the app, and the platform refuses what you
may not do. The platform checks every request.
The app's own identity
An app acts as its managed identity, not as you. To read secrets, its identity needs Secrets Reader on the vault — see Give a workload access. For other platform services, see Give a managed identity a role.