Skip to content
Stackship documentation Svenska

App ServiceUsers

Permissions

The actions that govern apps and slots, what each allows, and the roles that hold them.

Actions

Action Allows
apps/read See apps and their slots — including the values of their environment variables and scaling triggers — deployment history, revisions, metrics, certificate status and source; list the runtime stacks and compute plans
apps/write Create apps and slots; change their configuration; deploy, start, stop and restart; redeploy a version; roll back. Includes apps/delete
apps/delete Delete apps and slots
apps/scale Not checked by the portal or the API today: scaling is changed in the app's configuration, which needs apps/write
apps/readLogs Read container logs and build logs; list an app's instances
apps/readFiles Browse and download files on an app's disk
apps/writeFiles Upload, create, rename, move and delete files on an app's disk

apps/readLogs, apps/readFiles and apps/writeFiles are data actions: a role grants them only when it lists them as data actions, so managing an app does not by that alone let you read its logs or its files. Reading logs also needs boundaries/workloads/read and boundaries/workloads/readLogs, which the platform checks when it reads the app's pods; every role below that can read logs has them.

Other actions an app's page uses: choosing a repository needs kernel/deployments/read, the Activity tab needs kernel/activity/read, and the Operations tab needs kernel/operations/read.

Roles

Role Apps Logs Files
Reader See Read No
Apps Reader See No No
Apps Operator See, create, change, delete Read Read and change
Contributor, Owner See, create, change, delete Read Read and change
Platform Reader See No No
Platform Contributor, Platform Owner See, create, change, delete Read Read and change

Assign a role on a boundary, a resource group or a single app — see Role assignments. A role on an app covers its slots. All built-in roles are described in Built-in roles.

Caution

For anyone who also signs in to a cluster's Kubernetes API server, an assignment on a boundary or a resource group gives more there than in the portal:

  • Apps Operator — like Owner, Contributor, Platform Owner and Platform Contributor — carries pods/exec: a shell in every pod of the namespaces the assignment covers, not only in apps. The file actions reach the disk through it.
  • apps/write and apps/scale let the holder change the app's Kubernetes resource directly, the whole resource and without the platform's checks — apps/scale too, although the portal and the API do not use it.

See Kubernetes RBAC.

What the portal shows

On an app's page the portal hides what you cannot use: the Configuration tab and the Deploy, Start, Stop, Restart, Redeploy this version and Roll back buttons without apps/write, the Danger Zone without apps/delete, and the Files tab without apps/readFiles. On the Slots tab and on a slot's page only Restart, Stop and Start are hidden: Create Slot, the delete buttons, Deploy, the Configuration tab and the Danger Zone are shown to everyone who can see the app, and the platform refuses what you may not do. The platform checks every request.

The app's own identity

An app acts as its managed identity, not as you. To read secrets, its identity needs Secrets Reader on the vault — see Give a workload access. For other platform services, see Give a managed identity a role.