Permissions
The actions that govern key-value stores and their passwords, and the roles that hold them.
Actions
| Action | Allows |
|---|---|
valkey/read |
See stores, their configuration and revisions |
valkey/write |
Create and change stores; start, stop and restart them. Includes valkey/delete |
valkey/delete |
Delete stores |
valkey/readSecrets |
Show the connection details, which carry the password — also for a store without one |
valkey/writeSecrets |
Rotate the password — see Rotate the password |
valkey/readSecrets and valkey/writeSecrets are data actions: a role grants them only when it
lists them as such, so a role that can manage a store does not by that alone read its password.
There is no scale action and there are no snapshot actions: a store runs one server and keeps nothing
to snapshot.
Roles
| Role | See | Create, change, start, stop | Delete | Connection details | Rotate the password |
|---|---|---|---|---|---|
| Reader, Databases Reader | Yes | No | No | No | No |
| Databases Operator | Yes | Yes | Yes | Yes | Yes |
| Contributor, Owner | Yes | Yes | Yes | Yes | Yes |
Platform Owner and Platform Contributor hold every action in every boundary; Platform Reader can see stores. Assign roles on the boundary, the resource group or the store itself — see Role assignments.