Skip to content
Stackship documentation Svenska

Access control

How the platform decides who may do what — principals, roles, scopes, deny assignments and just-in-time access.

  • API reference — Every HTTP endpoint of the rbac module: authentication, IAM action, parameters, bodies and status codes.
  • Boundary trusts — Let the workload identities of one boundary be given roles in a boundary that belongs to another tenant.
  • Built-in roles at a glance — The roles that ship with the platform, what each grants, and what each leaves out.
  • Check access — Find out whether a principal holds an action at a scope, and which role or deny decides it.
  • Configuration reference — Configuration keys of the rbac module: sections, environment variables, types and defaults.
  • Custom roles — Create a role with exactly the actions you need, clone one, work with its JSON, and delete it.
  • Deny assignments — Block specific actions for specific principals at a scope, whatever roles they hold.
  • Invitation and password errors — The error codes the invitation, password-reset and password-change routes answer with, when each happens, and what to do about it.
  • IAM actions — Every IAM action, grouped by module, with the built-in roles that grant it.
  • IAM reference — The permissions of the platform: every IAM action and every built-in role.
  • Built-in roles — Every built-in role and the actions and data actions it grants.
  • Access control — How the platform decides who may do what — principals, roles, scopes, deny assignments and just-in-time access.
  • Just-in-time access — Request a role for a few hours, get it approved by an owner, activate it, and let it expire.
  • Kubernetes RBAC — How roles and assignments are written into each cluster's Kubernetes RBAC, and why a release can need a cluster administrator once.
  • Permissions — The actions that govern access control itself, what each task needs, and the actions that are only checked at the root scope.
  • Role assignments — Give a user, group or service principal a role at a boundary, resource group or resource, change it, and remove it.
  • Tenants and guests — Which principals a boundary can see and grant roles to, and what happens when a platform administrator reaches outside the tenant.