Permissions
The actions that govern jobs, and the roles that hold them.
Actions
| Action | Allows |
|---|---|
jobs/read |
List jobs and see them, including their environment variables |
jobs/write |
Create jobs; includes jobs/delete |
jobs/delete |
Delete jobs |
jobs/readLogs |
Read a job's output |
jobs/readLogs is a data action: a role only grants it when it lists it as such. Reading the
output also needs boundaries/workloads/read and boundaries/workloads/readLogs, which the
platform checks when it reads the job's pod; every role below that can read output has them.
Without boundaries/workloads/read the output route does not refuse; it answers
No pods found for job.
Roles
| Role | See | Create and delete | Output |
|---|---|---|---|
| Jobs Reader | Yes | No | Yes |
| Reader | Yes | No | Yes |
| Jobs Operator | Yes | Yes | Yes |
| Contributor, Owner | Yes | Yes | Yes |
| Platform Reader | Yes, in every boundary | No | No |
| Platform Contributor, Platform Owner | Yes, in every boundary | Yes | Yes |
Assign a role on a boundary or a resource group; see Role assignments.
Important
Anyone who can see a job reads its environment variables in plain text — Platform Reader included, in every boundary on the platform. Keep secrets out of them.