Skip to content
Stackship documentation Svenska

Stackship platformUsers

Permissions

The platform-core actions — clusters, deployment sources, operations, activity, platform settings — and the built-in roles that hold them.

These actions cover what the platform's core provides itself. Actions of resources — apps, databases, vaults and so on — are listed on each module's own permissions page.

Where actions are checked

Some actions are checked at the platform root (/). Only a role assigned at the root grants them, so in practice only the platform roles do; a boundary Owner does not hold them, even though the Owner role's definition includes most of them. The others are checked at the scope the request names: a boundary, a resource group or a resource.

Actions

Action Allows Checked at
kernel/clusters/read See the registered clusters root
kernel/clusters/write Register, change and delete clusters; issue join tokens; revoke agents root
kernel/platform/read See the platform's components, their status and the cluster topology root
kernel/platform/diagnose Inspect a platform component's pods, events and database internals root
kernel/deployments/read See a boundary's deployment sources, their repositories and credential health boundary
kernel/deployments/write Connect deployment sources; includes kernel/deployments/delete boundary
kernel/deployments/delete Delete deployment sources boundary
kernel/deployments/token Get a short-lived token to clone a source repository — held by platform services boundary
kernel/operations/read See operations and dismiss them from your notifications boundary, resource
kernel/activity/read Read a resource's activity log resource
kernel/activity/write Write activity records — nearly every role has it, so that changes can be recorded whichever role allowed them boundary
kernel/resourceStatus/read Receive live status updates for resources resource
kernel/emailSettings/manage View and change the SMTP settings root
kernel/emailTemplates/manage Edit, preview, restore and reset e-mail templates root
kernel/mcpSettings/manage Turn the MCP interface for AI clients on and off, and edit the hosts allowed to register a client root
kernel/telemetrySettings/manage View and change where the platform exports its own telemetry root
kernel/llmGateways/read, …/write, …/delete See, register and change, and delete LLM gateways root
kernel/llmGateways/resolve Resolve an LLM gateway's address and key — held by platform services only root

The catalogue also defines kernel/k8sChannel/* and kernel/crates/* actions, which the platform's modules and resource pages use internally.

Roles

Every built-in role except LLM Gateway Consumer also holds kernel/activity/write, so that the changes it allows can be recorded; the table leaves it out.

Role Kernel actions it holds
Platform Owner All of them
Platform Contributor All except kernel/clusters/write and kernel/platform/diagnose
Platform Reader kernel/platform/read, kernel/operations/read, kernel/activity/read, kernel/resourceStatus/read, kernel/llmGateways/read
Owner, Contributor The boundary-scoped ones: deployment sources, operations, activity, resource status
Reader kernel/operations/read, kernel/activity/read, kernel/resourceStatus/read, kernel/crates/read
Apps Reader, Apps Operator, Functions Operator kernel/deployments/read, kernel/operations/read, kernel/resourceStatus/read
Blueprints Operator kernel/deployments/read, kernel/operations/read, kernel/resourceStatus/read, kernel/crates/read
Blueprint Reader kernel/operations/read, kernel/resourceStatus/read, kernel/crates/read
Other scoped roles (Secrets, Databases, Jobs, Storage …) kernel/operations/read, kernel/resourceStatus/read
Deployment Token Broker kernel/deployments/token
LLM Gateway Consumer kernel/llmGateways/resolve

Reader, Blueprint Reader and Blueprints Operator also hold the data action kernel/crates/readLogs, and Blueprints Operator kernel/crates/exec. Platform Reader and Reader do not hold kernel/clusters/read or kernel/deployments/read.

Roles, scopes and how to assign them are described in Assign a role.