Permissions
The actions that govern vector stores, and the roles that hold them.
These actions govern what people and service accounts may do with a vector store on the platform. They do not limit what a client holding the API key may do inside Qdrant.
Actions
| Action | Allows |
|---|---|
qdrantcluster/read |
See vector stores, their configuration and status; show their endpoints |
qdrantcluster/write |
Create and change vector stores, including version, plan, replicas and networking; Start, Stop and Restart. Includes qdrantcluster/delete |
qdrantcluster/delete |
Delete vector stores |
qdrantcluster/scale |
Change the replica count through the scale endpoint (stsh qdrant scale), together with qdrantcluster/write |
qdrantcluster/readSecrets |
Show the API key, together with qdrantcluster/read |
qdrantcluster/writeSecrets |
Rotate the API key, together with qdrantcluster/write |
qdrantcluster/readSecrets and qdrantcluster/writeSecrets are data actions: a role only grants
them when it lists them as such.
Roles
| Role | See | Create, change, delete | Scale | Show the API key | Rotate the API key |
|---|---|---|---|---|---|
| Reader | Yes | No | No | No | No |
| Databases Reader | Yes | No | No | No | No |
| Databases Operator | Yes | Yes | Yes | Yes | Yes |
| Contributor, Owner | Yes | Yes | Yes | Yes | Yes |
Assign a role on a boundary or a resource group. A vector store's own assignments are on its Access Control tab. See Role assignments.
Caution
A role assigned on a single vector store, on its Access Control tab, is honoured only when showing the vector store's endpoints and showing or rotating its API key. Listing, opening, changing, scaling, stopping, starting, restarting and deleting the vector store check the role at a scope that such an assignment does not cover, and refuse it. Someone whose only role is on the vector store therefore cannot open it in the portal. To let someone work with one vector store, assign the role on its resource group.