Skip to content
Stackship documentation Svenska

Access controlUsers

IAM actions

Every IAM action, grouped by module, with the built-in roles that grant it.

Generated from the platform's RBAC catalogue — do not edit.

Kernel

Catalogue module kernel.

kernel/clusters/read

Clusters/Read — List and view registered clusters.

kernel/clusters/write

Clusters/Write — Create, update, or delete cluster registrations.

kernel/platform/read

Platform/Read — View the platform component map, component status, and cluster topology. Root-scoped: what the platform is made of belongs to no boundary, so a boundary-scoped grant must never reach it.

kernel/platform/diagnose

Platform/Diagnose — Inspect a platform component's pods, events and stall reasons, and the platform database's internals. Platform Owner only — pod names, restart counts, event messages and connection state are operator-grade detail a read-only platform role has no reason to hold.

kernel/deployments/read

Deployments/Read — Read deployment sources, installations, repositories, branches, and credential health.

kernel/deployments/write

Deployments/Write — Create deployment sources and ensure webhooks.

kernel/deployments/delete

Deployments/Delete — Delete a deployment source and revoke its credentials.

kernel/deployments/token

Deployments/Token — Mint a short-lived source-repo access token for cloning.

kernel/activity/read

Activity/Read — List activity records and read list-configuration metadata.

kernel/activity/write

Activity/Write — Append activity records for audit logging.

kernel/k8sChannel/read

Kubernetes Channel/Read — List and get Stackship custom resources via the in-cluster Kubernetes channel.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se * get, list, watch —

kernel/k8sChannel/write

Kubernetes Channel/Write — Create, update, or delete Stackship custom resources via the in-cluster Kubernetes channel.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se * get, list, watch, create, update, patch, delete —

kernel/k8sChannel/readSecretMetadata

Kubernetes Channel/Read Secret Metadata — List and read Kubernetes Secret objects with all material removed by the channel. Grants names, labels and annotations — never data or stringData. Granted to no built-in role by default: at boundary scope this enumerates tenant-chosen Secret names across every boundary, which is a capability to hand out deliberately rather than a read to fold into a broad role.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" secrets get, list, watch —

kernel/k8sChannel/readNamespacedRbac

Kubernetes Channel/Read Namespaced RBAC — List and read Kubernetes Roles and RoleBindings in a boundary's namespaces, so a permissions failure can be explained with the permissions that actually existed. Read-only — writing a permission object is how something grants itself more access, and that stays reconciler-only. Cluster-wide RBAC is not served at all: a ClusterRoleBinding listing maps the whole cluster's privilege graph.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
rbac.authorization.k8s.io roles, rolebindings get, list, watch —

kernel/k8sChannel/readNamespaceDiagnostics

Kubernetes Channel/Read Namespace Diagnostics — List and read Events, LimitRanges and ResourceQuotas — what the cluster said happened, and the limits it happened under. Read-only: raising your own ResourceQuota or LimitRange is a privilege change wearing a diagnostic's clothes.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" events, limitranges, resourcequotas get, list, watch —

kernel/operations/read

Operations/Read — List, view, and dismiss operations.

kernel/resourceStatus/read

ResourceStatus/Read — Subscribe to real-time resource status updates over SignalR.

kernel/crates/read

Crates/Read — Subscribe to real-time crate status updates over SignalR.

kernel/crates/readLogs

Crates/ReadLogs — Stream crate logs over SignalR.

kernel/crates/exec

Crates/Exec — Open an interactive terminal session against a crate.

kernel/emailTemplates/manage

EmailTemplates/Manage — List, edit, preview, test-send, restore versions, and reset email templates used for transactional emails. Root-scoped, Platform Owner only.

kernel/emailSettings/manage

EmailSettings/Manage — View and edit SMTP / email delivery settings (host, port, credentials, from address). Root-scoped, Platform Owner only.

kernel/mcpSettings/manage

McpSettings/Manage — Turn the MCP interface for AI clients on and off. Root-scoped, Platform Owner only — the switch decides whether an AI client can reach this installation's API at all.

kernel/telemetrySettings/manage

TelemetrySettings/Manage — View and edit where the platform exports its own errors, metrics and traces. Root-scoped, Platform Owner only — it decides whether platform telemetry leaves the perimeter at all, and to whom.

kernel/docsFeedback/export

DocsFeedback/Export — Download the docs feedback kept on this platform ("Did this help?" answers and docs searches that found nothing), to send to Stackship by hand. Root-scoped; held by the platform-wide admin roles through `*/*`. Not a read, so Platform Reader's `*/read` does not reach it: comments are free text. Submitting feedback needs no action.

kernel/llmGateways/read

LlmGateways/Read — List and view registered LLM gateways, their models and health. Never the API key. Root-scoped.

kernel/llmGateways/write

LlmGateways/Write — Register, change, verify and set the default LLM gateway, including replacing or removing its API key. Root-scoped.

kernel/llmGateways/delete

LlmGateways/Delete — Delete a registered LLM gateway. Root-scoped.

kernel/llmGateways/resolve

LlmGateways/Resolve — Resolve an LLM gateway over the channel — its URL, enabled models and API key. The reply is a credential, so platform services hold this through the LLM Gateway Consumer role rather than by module identity.

Apps

Catalogue module apps.

apps/read

Apps/Read — List and view apps, deployment slots, runtimes, metrics.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se apps get, list, watch —

apps/write

Apps/Write — Create or update apps and their configuration.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se apps get, list, watch, create, update, patch —

apps/delete

Apps/Delete — Delete apps.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se apps delete —

apps/scale

Apps/Scale — Scale an app's replica count or compute plan.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se apps patch, update —

apps/readLogs

Apps/Read Logs — Stream build and runtime logs for an app.

apps/readFiles

Apps/Read Files — List and download files on an app's persistent disk (/data), through the file-agent sidecar. Reaching the disk goes through pods/exec, and Kubernetes cannot scope pods/exec to one container or one argv — so this is exec-equivalent at the cluster layer and is deliberately NOT granted to reader tiers. See meta/docs/specs/pvc-file-browser.md §4.1.

apps/writeFiles

Apps/Write Files — Upload, move, rename and delete files on an app's persistent disk. Same exec-equivalence as apps/readFiles, plus the ability to change what the app reads on its next start.

Blueprints

Catalogue module blueprints.

blueprints/read

Blueprints/Read — List and view blueprint templates in the catalog.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se blueprints get, list, watch —

blueprints/templates/write

Blueprints/Templates/Write — Create, update or delete boundary-scoped blueprint templates. Safe to grant because a template renders into a container-instance spec and can only express what the public API can express — it cannot describe a privileged pod, a hostPath or an RBAC object, because the document shape has nowhere to put them. Built-in templates are seeded from disk and are not writable through this action.

Functions

Catalogue module functions.

functions/read

Functions/Read — List and view functions, namespaces, runtimes, metrics.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se functions, functionnamespaces get, list, watch —

functions/write

Functions/Write — Create or update functions and function namespaces.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se functions, functionnamespaces get, list, watch, create, update, patch —

functions/delete

Functions/Delete — Delete functions or function namespaces.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se functions, functionnamespaces delete —

functions/scale

Functions/Scale — Adjust a function's compute plan or concurrency.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se functions, functionnamespaces patch, update —

functions/readLogs

Functions/Read Logs — Stream build and runtime logs for a function.

Jobs

Catalogue module jobs.

jobs/read

Jobs/Read — List and view jobs.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
batch jobs get, list, watch —

jobs/write

Jobs/Write — Create or update jobs.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
batch jobs get, list, watch, create, update, patch —

jobs/delete

Jobs/Delete — Delete jobs.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
batch jobs delete, deletecollection —

jobs/readLogs

Jobs/Read Logs — Stream logs from job pods.

Managed Identities

Catalogue module managedIdentity.

managedidentities/read

Managed Identities/Read — List and view managed identities.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
identity.stackship.se managedidentities get, list, watch —

managedidentities/write

Managed Identities/Write — Create or update managed identities.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
identity.stackship.se managedidentities get, list, watch, create, update, patch —

managedidentities/delete

Managed Identities/Delete — Delete managed identities.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
identity.stackship.se managedidentities delete, deletecollection —

managedidentities/readSecrets

Managed Identities/Read Tokens — Issue or read tokens for a managed identity.

Secrets

Catalogue module secrets.

secretvault/read

Secret Vault/Read — View and list secret vaults.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se secretvaults get, list, watch —

secretvault/write

Secret Vault/Write — Create or update secret vaults.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se secretvaults get, list, watch, create, update, patch —

secretvault/delete

Secret Vault/Delete — Delete secret vaults.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se secretvaults delete —

secretvault/readSecrets

Secret Vault/Read Secrets — Read secret values (connection strings, passwords) from a vault.

secretvault/writeSecrets

Secret Vault/Write Secrets — Create, update, or rotate secrets inside a vault.

Databases — Postgres

Catalogue module databasesPostgres.

postgrescluster/read

Postgres Cluster/Read — View and list Postgres clusters.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
postgresql.cnpg.io clusters get, list, watch —

postgrescluster/write

Postgres Cluster/Write — Create or update Postgres clusters.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
postgresql.cnpg.io clusters get, list, watch, create, update, patch —

postgrescluster/delete

Postgres Cluster/Delete — Delete Postgres clusters.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
postgresql.cnpg.io clusters delete, deletecollection —

postgrescluster/scale

Postgres Cluster/Scale — Scale a Postgres cluster's replica count or compute plan.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
postgresql.cnpg.io clusters patch, update —

postgrescluster/createSnapshot

Postgres Cluster/Create Snapshot — Create a Velero backup snapshot of a Postgres cluster.

postgrescluster/restoreSnapshot

Postgres Cluster/Restore Snapshot — Restore a Postgres cluster from a snapshot.

postgrescluster/deleteSnapshot

Postgres Cluster/Delete Snapshot — Delete a Postgres cluster snapshot.

postgrescluster/readSecrets

Postgres Cluster/Read Secrets — Read connection strings and passwords for a Postgres cluster.

postgrescluster/writeSecrets

Postgres Cluster/Write Secrets — Rotate or update Postgres cluster credentials.

postgrescluster/dataRead

Postgres Cluster/Data Read — Browse rows via the structured row-browser endpoints.

postgrescluster/dataWrite

Postgres Cluster/Data Write — Insert, update, or delete rows via the structured row-browser endpoints.

postgrescluster/queryExecute

Postgres Cluster/Query Execute — Run read-only SQL (SELECT, EXPLAIN without ANALYZE) in the editor.

postgrescluster/queryExecuteWrite

Postgres Cluster/Query Execute Write — Run mutating SQL (INSERT/UPDATE/DELETE/MERGE, SELECT FOR UPDATE, LOCK) in the editor.

postgrescluster/schemaRead

Postgres Cluster/Schema Read — List schemas, tables, columns, and indexes.

postgrescluster/schemaWrite

Postgres Cluster/Schema Write — Create or alter database objects (CREATE TABLE/INDEX/VIEW, ALTER TABLE, VACUUM, REINDEX).

postgrescluster/schemaDrop

Postgres Cluster/Schema Drop — Drop or truncate database objects. Should be JIT-gated by default.

  • Data action: Yes
  • Granted by: no built-in role

Databases — SQL Server

Catalogue module databasesSqlServer.

sqlservercluster/read

SQL Server/Read — View and list SQL Server instances.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se sqlservers get, list, watch —

sqlservercluster/write

SQL Server/Write — Create or update SQL Server instances; start, stop, and restart.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se sqlservers get, list, watch, create, update, patch —

sqlservercluster/delete

SQL Server/Delete — Delete SQL Server instances.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se sqlservers delete —

sqlservercluster/scale

SQL Server/Scale — Scale a SQL Server instance's compute plan or storage.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se sqlservers patch, update —

sqlservercluster/createSnapshot

SQL Server/Create Snapshot — Create a Velero backup snapshot of a SQL Server instance.

sqlservercluster/restoreSnapshot

SQL Server/Restore Snapshot — Restore a SQL Server instance from a snapshot.

sqlservercluster/deleteSnapshot

SQL Server/Delete Snapshot — Delete a SQL Server instance snapshot.

sqlservercluster/readSecrets

SQL Server/Read Secrets — Read connection strings and the SA password for a SQL Server instance.

sqlservercluster/writeSecrets

SQL Server/Write Secrets — Rotate or update SQL Server instance credentials.

sqlservercluster/manageLicense

SQL Server/Manage License — Set or rotate the product key for paid (Standard/Enterprise) editions.

sqlservercluster/dataRead

SQL Server/Data Read — Browse rows via the structured row-browser endpoints.

sqlservercluster/dataWrite

SQL Server/Data Write — Insert, update, or delete rows via the structured row-browser endpoints.

sqlservercluster/queryExecute

SQL Server/Query Execute — Run read-only T-SQL (SELECT, SET SHOWPLAN) in the editor.

sqlservercluster/queryExecuteWrite

SQL Server/Query Execute Write — Run mutating T-SQL (INSERT/UPDATE/DELETE/MERGE) in the editor.

sqlservercluster/schemaRead

SQL Server/Schema Read — List schemas, tables, columns, and indexes (sys.* / INFORMATION_SCHEMA).

sqlservercluster/schemaWrite

SQL Server/Schema Write — Create or alter database objects (CREATE/ALTER TABLE/INDEX/VIEW, sp_rename).

sqlservercluster/schemaDrop

SQL Server/Schema Drop — Drop or truncate database objects. Should be JIT-gated by default.

Databases — Qdrant

Catalogue module databasesQdrant.

qdrantcluster/read

Qdrant Cluster/Read — View and list Qdrant clusters.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
qdrantoperator.io qdrantclusters get, list, watch —

qdrantcluster/write

Qdrant Cluster/Write — Create or update Qdrant clusters.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
qdrantoperator.io qdrantclusters get, list, watch, create, update, patch —

qdrantcluster/delete

Qdrant Cluster/Delete — Delete Qdrant clusters.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
qdrantoperator.io qdrantclusters delete, deletecollection —

qdrantcluster/scale

Qdrant Cluster/Scale — Scale a Qdrant cluster's replica count or compute plan.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
qdrantoperator.io qdrantclusters patch, update —

qdrantcluster/readSecrets

Qdrant Cluster/Read Secrets — Read API keys and connection information for a Qdrant cluster.

qdrantcluster/writeSecrets

Qdrant Cluster/Write Secrets — Rotate or update Qdrant cluster API keys.

Databases — Valkey

Catalogue module databasesValkey.

valkey/read

Valkey/Read — View and list Valkey instances.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se valkeys get, list, watch —

valkey/write

Valkey/Write — Create or update Valkey instances.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se valkeys get, list, watch, create, update, patch —

valkey/delete

Valkey/Delete — Delete Valkey instances.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se valkeys delete —

valkey/readSecrets

Valkey/Read Secrets — Read the password and connection information for a Valkey instance.

valkey/writeSecrets

Valkey/Write Secrets — Rotate the password for a Valkey instance. Restarts the instance, which empties the cache.

Workflows

Catalogue module workflows.

workflow/read

Workflow/Read — View and list workflows, including their graph and run history.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se workflows get, list, watch —

workflow/write

Workflow/Write — Create or update workflows and save new versions of their graph.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se workflows get, list, watch, create, update, patch —

workflow/delete

Workflow/Delete — Delete workflows.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se workflows delete —

workflow/trigger

Workflow/Trigger — Start a workflow run, and cancel or replay one. Runs execute with the workflow's own identity.

workflow/readStepIo

Workflow/Read Step Data — Read the inputs and outputs each node saw during a run. This is the data the workflow processed, verbatim.

  • Data action: Yes
  • Granted by: no built-in role

Container Instances

Catalogue module containerInstances.

containerinstance/read

Container Instance/Read — View and list container instances.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se containerinstances get, list, watch —

containerinstance/write

Container Instance/Write — Create or update container instances (including start/stop/restart).

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se containerinstances get, list, watch, create, update, patch —

containerinstance/delete

Container Instance/Delete — Delete container instances.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se containerinstances delete —

containerinstance/scale

Container Instance/Scale — Scale a container instance's replica count.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se containerinstances patch, update —

containerinstance/createSnapshot

Container Instance/Create Snapshot — Take a snapshot of a container instance's persistent volumes.

containerinstance/restoreSnapshot

Container Instance/Restore Snapshot — Restore a container instance's volumes from a snapshot, in place.

containerinstance/deleteSnapshot

Container Instance/Delete Snapshot — Delete a container instance snapshot.

containerinstance/readLogs

Container Instance/Read Logs — Stream container log lines from the pods backing a container instance.

containerinstance/exec

Container Instance/Exec Terminal — Open an interactive terminal into a pod backing a container instance. Commands are audited. Deliberately NOT granted to reader tiers — a shell in the pod is write access to everything the workload can reach, whatever the CRD-level verbs say.

containerinstance/readFiles

Container Instance/Read Files — List and download files on a container instance's persistent volumes, through the file-agent sidecar. Reaching the volume goes through pods/exec, and Kubernetes cannot scope pods/exec to one container or one argv — so this is exec-equivalent at the cluster layer and, like containerinstance/exec, is deliberately NOT granted to reader tiers. See meta/docs/specs/pvc-file-browser.md §4.1.

containerinstance/writeFiles

Container Instance/Write Files — Upload, move, rename and delete files on a container instance's persistent volumes. Same exec-equivalence as containerinstance/readFiles, plus the ability to change what the workload reads on its next start.

containerinstance/access

Container Instance/Access — Browser access to a container instance's auth-guarded endpoints. Enforced by the instance-auth gateway via an ingress auth subrequest, not by an API route — no kubernetesRules needed. Replaces blueprints/instances/access.

Static Web Apps

Catalogue module staticWebApps.

staticwebapp/read

Static Web App/Read — View and list static web apps, including deployment history.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se staticwebapps get, list, watch —

staticwebapp/write

Static Web App/Write — Create or update static web apps, including source, directory to serve and routing settings.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se staticwebapps get, list, watch, create, update, patch —

staticwebapp/delete

Static Web App/Delete — Delete static web apps.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se staticwebapps delete —

staticwebapp/scale

Static Web App/Scale — Scale a static web app's replica count.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se staticwebapps patch, update —

staticwebapp/deploy

Static Web App/Deploy — Trigger a deployment, or roll back to a previously deployed version.

staticwebapp/readLogs

Static Web App/Read Logs — Stream a static web app's nginx logs.

Boundaries

Catalogue module boundaries.

boundaries/create

Boundaries/Create — Create new boundaries.

boundaries/tenant/admin

Boundaries/Tenant Admin — Move a boundary to another tenant, new or existing. The boundary's people join the target tenant, which decides who they can see and how they sign in.

boundaries/delete

Boundaries/Delete — Delete boundaries.

boundaries/list

Boundaries/List — List all boundaries across the platform.

boundaries/read

Boundaries/Read — View a specific boundary.

boundaries/manage

Boundaries/Manage — Update boundary configuration.

boundaries/projections/read

Boundaries/Projections Read — View boundary projections in clusters.

boundaries/projections/manage

Boundaries/Projections Manage — Attach or detach boundaries to clusters.

boundaries/projections/write

Boundaries/Projections Write — Write the Boundary custom resource into a projected cluster. Distinct from Manage, which decides *whether* a boundary is projected into a cluster; this maintains the resource that projection produces, and is what the boundary CR reconciler performs through the Kubernetes channel.

boundaries/projections/delete

Boundaries/Projections Delete — Remove the Boundary custom resource from a cluster.

boundaries/members/read

Boundaries/Members Read — View boundary membership and role assignments.

boundaries/members/manage

Boundaries/Members Manage — Add or remove members from a boundary.

boundaries/invitations/read

Boundaries/Invitations Read — View pending, accepted, revoked, and expired invitations on a boundary.

boundaries/invitations/create

Boundaries/Invitations Create — Send, revoke, and resend boundary invitations. Includes the implicit ability to read invitations on the boundary (a strict superset of boundaries/invitations/read).

boundaries/network/read

Boundaries/Network Read — See how a boundary's network is allowed to behave: which connections are permitted or blocked, why a connection was blocked, and the "can this reach that?" check. Reads the module's own projected policy set, never the cluster, so it carries no Kubernetes rules.

boundaries/workloads/read

Boundaries/Workloads Read — View workloads (pods, services, configmaps) within a boundary.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" pods, services, configmaps get, list, watch —
platform.stackship.se backuppolicies, restorerequests get, list, watch —

Crosslink/Admin — Enable or disable cross-cluster connectivity for a boundary, choose the hub cluster, and rotate the boundary CA. Opting an individual resource in rides on that resource's own write permission, and reading topology rides on boundaries/read, so this is the only Crosslink-specific action.

boundaries/workloads/manage

Boundaries/Workloads Manage — Create, update, and delete workloads within a boundary.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" pods, services, configmaps get, list, watch, create, update, patch, delete —
apps deployments, statefulsets, replicasets get, list, watch, create, update, patch, delete —
platform.stackship.se backuppolicies get, list, watch, create, update, patch, delete —
platform.stackship.se restorerequests get, list, watch, create —

boundaries/workloads/readLogs

Boundaries/Workloads Read Logs — Stream container logs from pods within a boundary's resource group. The kernel re-authorizes pod log stream calls under this action regardless of which module initiated them (e.g. apps build-logs, jobs runs, blueprints crates), so any role that needs to follow container logs through the portal needs this data action — the per-module `*/readLogs` actions cover the route gate, this one covers the kernel re-auth on the pod log stream.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" pods/log get, list —

Boundaries (Data Plane)

Catalogue module boundariesData.

pods/exec

Pods/Exec — Open an exec session into a pod.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" pods/exec create —

pods/portForward

Pods/Port Forward — Open a port-forward tunnel to a pod.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" pods/portforward create —

pods/attach

Pods/Attach — Attach to a running container in a pod.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" pods/attach create —

pods/log

Pods/Log — Read log output from a pod.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" pods/log get —

secrets/readSecretData

Secrets/Read Secret Data — Read the actual secret payload from a Kubernetes Secret.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" secrets get —

Resource Groups

Catalogue module resource-groups.

resourcegroups/read

Resource Groups/Read — List and view resource groups.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" namespaces get, list, watch —

resourcegroups/write

Resource Groups/Write — Create resource groups and their Kubernetes namespaces.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" namespaces get, list, watch, create, update, patch —

resourcegroups/delete

Resource Groups/Delete — Delete resource groups and their Kubernetes namespaces.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
"" namespaces get, list, watch, delete —

Sentinel

Catalogue module sentinel.

sentinel/read

Sentinel/Read — List and view security analysis jobs, findings, alerts, and resource configurations.

sentinel/write

Sentinel/Write — Update finding status and manage resource-specific Sentinel configurations.

sentinel/admin

Sentinel/Admin — Read cluster-wide (platform-scoped) sentinel findings.

Monitoring

Catalogue module monitoring.

monitoring/platform/read

Monitoring/Platform/Read — Read cluster-wide CPU, memory and storage health and platform-scoped alerts. Root-scoped: cluster health belongs to no boundary, so a boundary-scoped grant must never reach it.

monitoring/platform/alerts/write

Monitoring/Platform/Alerts/Write — Raise and clear a platform-scoped alert on behalf of another platform component. Root-scoped, and separate from the read because the roles that hold monitoring/platform/read are read-only platform roles. Held by module service accounts through Platform Alert Publisher, by no human role.

monitoring/read

Monitoring/Read — View resource metrics, alerts, and monitoring dashboards.

Compliance

Catalogue module compliance.

compliance/read

Compliance/Read — View compliance framework dashboards (GDPR, NIS2, ISO 27001) and aggregated control status. No backend endpoints today — the action gates the portal page; Platform Reader / Owner pick it up via the `*/read` wildcard.

Policies

Catalogue module policies.

policies/read

Policies/Read — List and view the policies in force in a boundary.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se policies get, list, watch —

policies/write

Policies/Write — Create, update, and delete policies within a boundary. Granted at boundary scope to Platform Owner, Platform Contributor, Boundary Owner, and Boundary Contributor.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se policies create, update, patch, delete —

S3 Storage

Catalogue module s3.

s3storageaccounts/read

StorageAccounts/Read — List and view S3 storage accounts, capacity, and usage.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se s3storageaccounts get, list, watch —

s3storageaccounts/write

StorageAccounts/Write — Create or update S3 storage accounts and their endpoint configuration.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se s3storageaccounts get, list, watch, create, update, patch —

s3storageaccounts/delete

StorageAccounts/Delete — Delete S3 storage accounts. Honours the spec.storage.retainOnDelete flag for the underlying PVC.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se s3storageaccounts delete —

s3storageaccounts/admin

StorageAccounts/Admin — Toggle administrative settings (allowS3ApiBucketLifecycle, retainOnDelete) on an existing account.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se s3storageaccounts get, list, watch, patch, update —

s3buckets/read

S3/Buckets/Read — List and view buckets within an S3 storage account.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se s3storageaccounts get, list, watch —

s3buckets/write

S3/Buckets/Write — Create buckets within an S3 storage account (portal path AND S3 API path).

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se s3storageaccounts get, list, patch —

s3buckets/delete

S3/Buckets/Delete — Delete buckets within an S3 storage account.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se s3storageaccounts get, list, patch —

s3objects/read

S3/Objects/Read — Read objects via SigV4-authorized GetObject, HeadObject, ListObjectsV2, and ListParts.

s3objects/write

S3/Objects/Write — Write objects via SigV4-authorized PutObject, CopyObject, and multipart upload.

s3objects/delete

S3/Objects/Delete — Delete objects via SigV4-authorized DeleteObject and DeleteObjects (batch).

s3accesskeys/read

S3/AccessKeys/Read — List and view S3 access keys (never includes the SecretAccessKey).

s3accesskeys/write

S3/AccessKeys/Write — Issue, update, or rotate S3 access keys. The SecretAccessKey is returned exactly once on issuance.

s3accesskeys/delete

S3/AccessKeys/Delete — Revoke (delete) S3 access keys.

s3sts/issue

S3/STS/Issue — Mint short-lived STS sessions (900-43200s) for an S3 storage account.

s3/audit/read

S3/Audit/Read — Read per-operation S3 data-plane audit events for a storage account.

Registry

Catalogue module registry.

registry/audit/read

Registry/Audit/Read — Query the registry audit log (push, pull and delete events) and view retention sweep history.

registry/retention/manage

Registry/Retention/Manage — Trigger a registry retention sweep on demand.

Lifecycle

Catalogue module lifecycle.

lifecycle/view

Lifecycle/View — View the component registry, releases, rollout plans, and rollout status.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se componentrollouts get, list, watch —

lifecycle/plan

Lifecycle/Plan — Create and validate rollout plans.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se componentrollouts get, list, watch —

lifecycle/execute

Lifecycle/Execute — Execute, pause, and resume rollouts.

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se componentrollouts get, list, watch, create, update, patch —

lifecycle/rollback

Lifecycle/Rollback — Initiate rollbacks (re-targets each component's previous image; blocked past a contract boundary).

Also projected into Kubernetes RBAC for principals holding it:

API group Resources Verbs Names
platform.stackship.se componentrollouts get, list, watch, create, update, patch —

lifecycle/install

Lifecycle/Install — Install new platform components discovered on the release feed (provisioning runs inside the lifecycle module — no ComponentRollout CR involved).

lifecycle/backupsManage

Lifecycle/Backups Manage — Change the platform's backup target and daily backup schedule (the target change runs as a dependency rollout of Velero; the module's own account performs the writes, so no caller-side Kubernetes rule is needed).

Catalogue module search.

search/read

Search/Read — Execute searches across resources within a boundary.

RBAC

Catalogue module rbac.

rbac/projector/apply

Rbac/Projector Apply — Apply the platform's own RBAC to every cluster, acting as the caller. Decides who may ask; each cluster's API server decides what they may actually write, against their own bearer — so holding this without the underlying Kubernetes rights gets a refusal from the cluster rather than an escalation.

rbac/projector/read

Rbac/Projector Read — Read the RBAC manifest a cluster must have before the platform can project IAM into it — the projector ServiceAccount, the permission ceiling derived from this catalogue, and the binding between them. Reading it is reading the upper bound on what the platform can ever grant in that cluster, which is what an operator inspects before applying it.

rbac/members/read

Members/Read — List members of a tenant.

rbac/members/write

Members/Write — Invite, remove, and manage tenant members.

rbac/members/admin

Members/Admin — Cross-tenant membership management — platform-admin only.

rbac/idpBindings/admin

IdpBindings/Admin — Manage tenant→Keycloak-IdP-alias bindings — platform-admin only.

rbac/boundaryTrusts/admin

BoundaryTrusts/Admin — Create and remove trusts that let one boundary's workload identities be granted roles in another, including across tenants — platform-admin only.

rbac/users/list

Users/List — Search all Keycloak realm users without the per-tenant filter. Granted to platform-level roles for cross-tenant administration; everyone else only sees principals already mirrored into TenantMembership for the tenant whose boundary they're operating in.