IAM actions
Every IAM action, grouped by module, with the built-in roles that grant it.
Generated from the platform's RBAC catalogue — do not edit.
Kernel
Catalogue module kernel.
kernel/clusters/read
Clusters/Read — List and view registered clusters.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/clusters/write
Clusters/Write — Create, update, or delete cluster registrations.
- Data action: No
- Granted by: Platform Owner
kernel/platform/read
Platform/Read — View the platform component map, component status, and cluster topology. Root-scoped: what the platform is made of belongs to no boundary, so a boundary-scoped grant must never reach it.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
kernel/platform/diagnose
Platform/Diagnose — Inspect a platform component's pods, events and stall reasons, and the platform database's internals. Platform Owner only — pod names, restart counts, event messages and connection state are operator-grade detail a read-only platform role has no reason to hold.
- Data action: No
- Granted by: Contributor, Owner, Platform Owner
kernel/deployments/read
Deployments/Read — Read deployment sources, installations, repositories, branches, and credential health.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprints Operator, Contributor, Functions Operator, Owner, Platform Contributor, Platform Owner
kernel/deployments/write
Deployments/Write — Create deployment sources and ensure webhooks.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/deployments/delete
Deployments/Delete — Delete a deployment source and revoke its credentials.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/deployments/token
Deployments/Token — Mint a short-lived source-repo access token for cloning.
- Data action: No
- Granted by: Contributor, Deployment Token Broker, Owner, Platform Contributor, Platform Owner
kernel/activity/read
Activity/Read — List activity records and read list-configuration metadata.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
kernel/activity/write
Activity/Write — Append activity records for audit logging.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Deployment Token Broker, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Alert Publisher, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
kernel/k8sChannel/read
Kubernetes Channel/Read — List and get Stackship custom resources via the in-cluster Kubernetes channel.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
* |
get, list, watch |
— |
kernel/k8sChannel/write
Kubernetes Channel/Write — Create, update, or delete Stackship custom resources via the in-cluster Kubernetes channel.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
* |
get, list, watch, create, update, patch, delete |
— |
kernel/k8sChannel/readSecretMetadata
Kubernetes Channel/Read Secret Metadata — List and read Kubernetes Secret objects with all material removed by the channel. Grants names, labels and annotations — never data or stringData. Granted to no built-in role by default: at boundary scope this enumerates tenant-chosen Secret names across every boundary, which is a capability to hand out deliberately rather than a read to fold into a broad role.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
secrets |
get, list, watch |
— |
kernel/k8sChannel/readNamespacedRbac
Kubernetes Channel/Read Namespaced RBAC — List and read Kubernetes Roles and RoleBindings in a boundary's namespaces, so a permissions failure can be explained with the permissions that actually existed. Read-only — writing a permission object is how something grants itself more access, and that stays reconciler-only. Cluster-wide RBAC is not served at all: a ClusterRoleBinding listing maps the whole cluster's privilege graph.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
rbac.authorization.k8s.io |
roles, rolebindings |
get, list, watch |
— |
kernel/k8sChannel/readNamespaceDiagnostics
Kubernetes Channel/Read Namespace Diagnostics — List and read Events, LimitRanges and ResourceQuotas — what the cluster said happened, and the limits it happened under. Read-only: raising your own ResourceQuota or LimitRange is a privilege change wearing a diagnostic's clothes.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
events, limitranges, resourcequotas |
get, list, watch |
— |
kernel/operations/read
Operations/Read — List, view, and dismiss operations.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
kernel/resourceStatus/read
ResourceStatus/Read — Subscribe to real-time resource status updates over SignalR.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
kernel/crates/read
Crates/Read — Subscribe to real-time crate status updates over SignalR.
- Data action: No
- Granted by: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
kernel/crates/readLogs
Crates/ReadLogs — Stream crate logs over SignalR.
- Data action: Yes
- Granted by: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
kernel/crates/exec
Crates/Exec — Open an interactive terminal session against a crate.
- Data action: Yes
- Granted by: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
kernel/emailTemplates/manage
EmailTemplates/Manage — List, edit, preview, test-send, restore versions, and reset email templates used for transactional emails. Root-scoped, Platform Owner only.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/emailSettings/manage
EmailSettings/Manage — View and edit SMTP / email delivery settings (host, port, credentials, from address). Root-scoped, Platform Owner only.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/mcpSettings/manage
McpSettings/Manage — Turn the MCP interface for AI clients on and off. Root-scoped, Platform Owner only — the switch decides whether an AI client can reach this installation's API at all.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/telemetrySettings/manage
TelemetrySettings/Manage — View and edit where the platform exports its own errors, metrics and traces. Root-scoped, Platform Owner only — it decides whether platform telemetry leaves the perimeter at all, and to whom.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/docsFeedback/export
DocsFeedback/Export — Download the docs feedback kept on this platform ("Did this help?" answers and docs searches that found nothing), to send to Stackship by hand. Root-scoped; held by the platform-wide admin roles through `*/*`. Not a read, so Platform Reader's `*/read` does not reach it: comments are free text. Submitting feedback needs no action.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/llmGateways/read
LlmGateways/Read — List and view registered LLM gateways, their models and health. Never the API key. Root-scoped.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
kernel/llmGateways/write
LlmGateways/Write — Register, change, verify and set the default LLM gateway, including replacing or removing its API key. Root-scoped.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/llmGateways/delete
LlmGateways/Delete — Delete a registered LLM gateway. Root-scoped.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
kernel/llmGateways/resolve
LlmGateways/Resolve — Resolve an LLM gateway over the channel — its URL, enabled models and API key. The reply is a credential, so platform services hold this through the LLM Gateway Consumer role rather than by module identity.
- Data action: No
- Granted by: Contributor, LLM Gateway Consumer, Owner, Platform Contributor, Platform Owner
Apps
Catalogue module apps.
apps/read
Apps/Read — List and view apps, deployment slots, runtimes, metrics.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
apps |
get, list, watch |
— |
apps/write
Apps/Write — Create or update apps and their configuration.
- Data action: No
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
apps |
get, list, watch, create, update, patch |
— |
apps/delete
Apps/Delete — Delete apps.
- Data action: No
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
apps |
delete |
— |
apps/scale
Apps/Scale — Scale an app's replica count or compute plan.
- Data action: No
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
apps |
patch, update |
— |
apps/readLogs
Apps/Read Logs — Stream build and runtime logs for an app.
- Data action: Yes
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
apps/readFiles
Apps/Read Files — List and download files on an app's persistent disk (/data), through the file-agent sidecar. Reaching the disk goes through pods/exec, and Kubernetes cannot scope pods/exec to one container or one argv — so this is exec-equivalent at the cluster layer and is deliberately NOT granted to reader tiers. See meta/docs/specs/pvc-file-browser.md §4.1.
- Data action: Yes
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
apps/writeFiles
Apps/Write Files — Upload, move, rename and delete files on an app's persistent disk. Same exec-equivalence as apps/readFiles, plus the ability to change what the app reads on its next start.
- Data action: Yes
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Blueprints
Catalogue module blueprints.
blueprints/read
Blueprints/Read — List and view blueprint templates in the catalog.
- Data action: No
- Granted by: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
blueprints |
get, list, watch |
— |
blueprints/templates/write
Blueprints/Templates/Write — Create, update or delete boundary-scoped blueprint templates. Safe to grant because a template renders into a container-instance spec and can only express what the public API can express — it cannot describe a privileged pod, a hostPath or an RBAC object, because the document shape has nowhere to put them. Built-in templates are seeded from disk and are not writable through this action.
- Data action: No
- Granted by: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
Functions
Catalogue module functions.
functions/read
Functions/Read — List and view functions, namespaces, runtimes, metrics.
- Data action: No
- Granted by: Contributor, Functions Operator, Functions Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
functions, functionnamespaces |
get, list, watch |
— |
functions/write
Functions/Write — Create or update functions and function namespaces.
- Data action: No
- Granted by: Contributor, Functions Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
functions, functionnamespaces |
get, list, watch, create, update, patch |
— |
functions/delete
Functions/Delete — Delete functions or function namespaces.
- Data action: No
- Granted by: Contributor, Functions Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
functions, functionnamespaces |
delete |
— |
functions/scale
Functions/Scale — Adjust a function's compute plan or concurrency.
- Data action: No
- Granted by: Contributor, Functions Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
functions, functionnamespaces |
patch, update |
— |
functions/readLogs
Functions/Read Logs — Stream build and runtime logs for a function.
- Data action: Yes
- Granted by: Contributor, Functions Operator, Functions Reader, Owner, Platform Contributor, Platform Owner, Reader
Jobs
Catalogue module jobs.
jobs/read
Jobs/Read — List and view jobs.
- Data action: No
- Granted by: Contributor, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
batch |
jobs |
get, list, watch |
— |
jobs/write
Jobs/Write — Create or update jobs.
- Data action: No
- Granted by: Contributor, Jobs Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
batch |
jobs |
get, list, watch, create, update, patch |
— |
jobs/delete
Jobs/Delete — Delete jobs.
- Data action: No
- Granted by: Contributor, Jobs Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
batch |
jobs |
delete, deletecollection |
— |
jobs/readLogs
Jobs/Read Logs — Stream logs from job pods.
- Data action: Yes
- Granted by: Contributor, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Reader
Managed Identities
Catalogue module managedIdentity.
managedidentities/read
Managed Identities/Read — List and view managed identities.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
identity.stackship.se |
managedidentities |
get, list, watch |
— |
managedidentities/write
Managed Identities/Write — Create or update managed identities.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
identity.stackship.se |
managedidentities |
get, list, watch, create, update, patch |
— |
managedidentities/delete
Managed Identities/Delete — Delete managed identities.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
identity.stackship.se |
managedidentities |
delete, deletecollection |
— |
managedidentities/readSecrets
Managed Identities/Read Tokens — Issue or read tokens for a managed identity.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Secrets
Catalogue module secrets.
secretvault/read
Secret Vault/Read — View and list secret vaults.
- Data action: No
- Granted by: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
secretvaults |
get, list, watch |
— |
secretvault/write
Secret Vault/Write — Create or update secret vaults.
- Data action: No
- Granted by: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Secrets Writer
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
secretvaults |
get, list, watch, create, update, patch |
— |
secretvault/delete
Secret Vault/Delete — Delete secret vaults.
- Data action: No
- Granted by: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Secrets Writer
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
secretvaults |
delete |
— |
secretvault/readSecrets
Secret Vault/Read Secrets — Read secret values (connection strings, passwords) from a vault.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Secrets Reader, Secrets Writer
secretvault/writeSecrets
Secret Vault/Write Secrets — Create, update, or rotate secrets inside a vault.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Secrets Writer
Databases — Postgres
Catalogue module databasesPostgres.
postgrescluster/read
Postgres Cluster/Read — View and list Postgres clusters.
- Data action: No
- Granted by: Contributor, Database Explorer, Databases Operator, Databases Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
postgresql.cnpg.io |
clusters |
get, list, watch |
— |
postgrescluster/write
Postgres Cluster/Write — Create or update Postgres clusters.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
postgresql.cnpg.io |
clusters |
get, list, watch, create, update, patch |
— |
postgrescluster/delete
Postgres Cluster/Delete — Delete Postgres clusters.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
postgresql.cnpg.io |
clusters |
delete, deletecollection |
— |
postgrescluster/scale
Postgres Cluster/Scale — Scale a Postgres cluster's replica count or compute plan.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
postgresql.cnpg.io |
clusters |
patch, update |
— |
postgrescluster/createSnapshot
Postgres Cluster/Create Snapshot — Create a Velero backup snapshot of a Postgres cluster.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/restoreSnapshot
Postgres Cluster/Restore Snapshot — Restore a Postgres cluster from a snapshot.
- Data action: No
- Granted by: Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/deleteSnapshot
Postgres Cluster/Delete Snapshot — Delete a Postgres cluster snapshot.
- Data action: No
- Granted by: Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/readSecrets
Postgres Cluster/Read Secrets — Read connection strings and passwords for a Postgres cluster.
- Data action: Yes
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/writeSecrets
Postgres Cluster/Write Secrets — Rotate or update Postgres cluster credentials.
- Data action: Yes
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/dataRead
Postgres Cluster/Data Read — Browse rows via the structured row-browser endpoints.
- Data action: Yes
- Granted by: Database Explorer
postgrescluster/dataWrite
Postgres Cluster/Data Write — Insert, update, or delete rows via the structured row-browser endpoints.
- Data action: Yes
- Granted by: Database Explorer
postgrescluster/queryExecute
Postgres Cluster/Query Execute — Run read-only SQL (SELECT, EXPLAIN without ANALYZE) in the editor.
- Data action: Yes
- Granted by: Database Explorer
postgrescluster/queryExecuteWrite
Postgres Cluster/Query Execute Write — Run mutating SQL (INSERT/UPDATE/DELETE/MERGE, SELECT FOR UPDATE, LOCK) in the editor.
- Data action: Yes
- Granted by: Database Explorer
postgrescluster/schemaRead
Postgres Cluster/Schema Read — List schemas, tables, columns, and indexes.
- Data action: Yes
- Granted by: Database Explorer
postgrescluster/schemaWrite
Postgres Cluster/Schema Write — Create or alter database objects (CREATE TABLE/INDEX/VIEW, ALTER TABLE, VACUUM, REINDEX).
- Data action: Yes
- Granted by: Database Explorer
postgrescluster/schemaDrop
Postgres Cluster/Schema Drop — Drop or truncate database objects. Should be JIT-gated by default.
- Data action: Yes
- Granted by: no built-in role
Databases — SQL Server
Catalogue module databasesSqlServer.
sqlservercluster/read
SQL Server/Read — View and list SQL Server instances.
- Data action: No
- Granted by: Contributor, Database Explorer, Databases Operator, Databases Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
sqlservers |
get, list, watch |
— |
sqlservercluster/write
SQL Server/Write — Create or update SQL Server instances; start, stop, and restart.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
sqlservers |
get, list, watch, create, update, patch |
— |
sqlservercluster/delete
SQL Server/Delete — Delete SQL Server instances.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
sqlservers |
delete |
— |
sqlservercluster/scale
SQL Server/Scale — Scale a SQL Server instance's compute plan or storage.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
sqlservers |
patch, update |
— |
sqlservercluster/createSnapshot
SQL Server/Create Snapshot — Create a Velero backup snapshot of a SQL Server instance.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/restoreSnapshot
SQL Server/Restore Snapshot — Restore a SQL Server instance from a snapshot.
- Data action: No
- Granted by: Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/deleteSnapshot
SQL Server/Delete Snapshot — Delete a SQL Server instance snapshot.
- Data action: No
- Granted by: Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/readSecrets
SQL Server/Read Secrets — Read connection strings and the SA password for a SQL Server instance.
- Data action: Yes
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/writeSecrets
SQL Server/Write Secrets — Rotate or update SQL Server instance credentials.
- Data action: Yes
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/manageLicense
SQL Server/Manage License — Set or rotate the product key for paid (Standard/Enterprise) editions.
- Data action: Yes
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/dataRead
SQL Server/Data Read — Browse rows via the structured row-browser endpoints.
- Data action: Yes
- Granted by: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/dataWrite
SQL Server/Data Write — Insert, update, or delete rows via the structured row-browser endpoints.
- Data action: Yes
- Granted by: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/queryExecute
SQL Server/Query Execute — Run read-only T-SQL (SELECT, SET SHOWPLAN) in the editor.
- Data action: Yes
- Granted by: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/queryExecuteWrite
SQL Server/Query Execute Write — Run mutating T-SQL (INSERT/UPDATE/DELETE/MERGE) in the editor.
- Data action: Yes
- Granted by: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/schemaRead
SQL Server/Schema Read — List schemas, tables, columns, and indexes (sys.* / INFORMATION_SCHEMA).
- Data action: Yes
- Granted by: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/schemaWrite
SQL Server/Schema Write — Create or alter database objects (CREATE/ALTER TABLE/INDEX/VIEW, sp_rename).
- Data action: Yes
- Granted by: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/schemaDrop
SQL Server/Schema Drop — Drop or truncate database objects. Should be JIT-gated by default.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Databases — Qdrant
Catalogue module databasesQdrant.
qdrantcluster/read
Qdrant Cluster/Read — View and list Qdrant clusters.
- Data action: No
- Granted by: Contributor, Databases Operator, Databases Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
qdrantoperator.io |
qdrantclusters |
get, list, watch |
— |
qdrantcluster/write
Qdrant Cluster/Write — Create or update Qdrant clusters.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
qdrantoperator.io |
qdrantclusters |
get, list, watch, create, update, patch |
— |
qdrantcluster/delete
Qdrant Cluster/Delete — Delete Qdrant clusters.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
qdrantoperator.io |
qdrantclusters |
delete, deletecollection |
— |
qdrantcluster/scale
Qdrant Cluster/Scale — Scale a Qdrant cluster's replica count or compute plan.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
qdrantoperator.io |
qdrantclusters |
patch, update |
— |
qdrantcluster/readSecrets
Qdrant Cluster/Read Secrets — Read API keys and connection information for a Qdrant cluster.
- Data action: Yes
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
qdrantcluster/writeSecrets
Qdrant Cluster/Write Secrets — Rotate or update Qdrant cluster API keys.
- Data action: Yes
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Databases — Valkey
Catalogue module databasesValkey.
valkey/read
Valkey/Read — View and list Valkey instances.
- Data action: No
- Granted by: Contributor, Databases Operator, Databases Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
valkeys |
get, list, watch |
— |
valkey/write
Valkey/Write — Create or update Valkey instances.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
valkeys |
get, list, watch, create, update, patch |
— |
valkey/delete
Valkey/Delete — Delete Valkey instances.
- Data action: No
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
valkeys |
delete |
— |
valkey/readSecrets
Valkey/Read Secrets — Read the password and connection information for a Valkey instance.
- Data action: Yes
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
valkey/writeSecrets
Valkey/Write Secrets — Rotate the password for a Valkey instance. Restarts the instance, which empties the cache.
- Data action: Yes
- Granted by: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Workflows
Catalogue module workflows.
workflow/read
Workflow/Read — View and list workflows, including their graph and run history.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
workflows |
get, list, watch |
— |
workflow/write
Workflow/Write — Create or update workflows and save new versions of their graph.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
workflows |
get, list, watch, create, update, patch |
— |
workflow/delete
Workflow/Delete — Delete workflows.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
workflows |
delete |
— |
workflow/trigger
Workflow/Trigger — Start a workflow run, and cancel or replay one. Runs execute with the workflow's own identity.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
workflow/readStepIo
Workflow/Read Step Data — Read the inputs and outputs each node saw during a run. This is the data the workflow processed, verbatim.
- Data action: Yes
- Granted by: no built-in role
Container Instances
Catalogue module containerInstances.
containerinstance/read
Container Instance/Read — View and list container instances.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
containerinstances |
get, list, watch |
— |
containerinstance/write
Container Instance/Write — Create or update container instances (including start/stop/restart).
- Data action: No
- Granted by: Apps Operator, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
containerinstances |
get, list, watch, create, update, patch |
— |
containerinstance/delete
Container Instance/Delete — Delete container instances.
- Data action: No
- Granted by: Apps Operator, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
containerinstances |
delete |
— |
containerinstance/scale
Container Instance/Scale — Scale a container instance's replica count.
- Data action: No
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
containerinstances |
patch, update |
— |
containerinstance/createSnapshot
Container Instance/Create Snapshot — Take a snapshot of a container instance's persistent volumes.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
containerinstance/restoreSnapshot
Container Instance/Restore Snapshot — Restore a container instance's volumes from a snapshot, in place.
- Data action: No
- Granted by: Owner, Platform Contributor, Platform Owner
containerinstance/deleteSnapshot
Container Instance/Delete Snapshot — Delete a container instance snapshot.
- Data action: No
- Granted by: Owner, Platform Contributor, Platform Owner
containerinstance/readLogs
Container Instance/Read Logs — Stream container log lines from the pods backing a container instance.
- Data action: Yes
- Granted by: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
containerinstance/exec
Container Instance/Exec Terminal — Open an interactive terminal into a pod backing a container instance. Commands are audited. Deliberately NOT granted to reader tiers — a shell in the pod is write access to everything the workload can reach, whatever the CRD-level verbs say.
- Data action: Yes
- Granted by: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
containerinstance/readFiles
Container Instance/Read Files — List and download files on a container instance's persistent volumes, through the file-agent sidecar. Reaching the volume goes through pods/exec, and Kubernetes cannot scope pods/exec to one container or one argv — so this is exec-equivalent at the cluster layer and, like containerinstance/exec, is deliberately NOT granted to reader tiers. See meta/docs/specs/pvc-file-browser.md §4.1.
- Data action: Yes
- Granted by: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
containerinstance/writeFiles
Container Instance/Write Files — Upload, move, rename and delete files on a container instance's persistent volumes. Same exec-equivalence as containerinstance/readFiles, plus the ability to change what the workload reads on its next start.
- Data action: Yes
- Granted by: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
containerinstance/access
Container Instance/Access — Browser access to a container instance's auth-guarded endpoints. Enforced by the instance-auth gateway via an ingress auth subrequest, not by an API route — no kubernetesRules needed. Replaces blueprints/instances/access.
- Data action: Yes
- Granted by: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
Static Web Apps
Catalogue module staticWebApps.
staticwebapp/read
Static Web App/Read — View and list static web apps, including deployment history.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
staticwebapps |
get, list, watch |
— |
staticwebapp/write
Static Web App/Write — Create or update static web apps, including source, directory to serve and routing settings.
- Data action: No
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
staticwebapps |
get, list, watch, create, update, patch |
— |
staticwebapp/delete
Static Web App/Delete — Delete static web apps.
- Data action: No
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
staticwebapps |
delete |
— |
staticwebapp/scale
Static Web App/Scale — Scale a static web app's replica count.
- Data action: No
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
staticwebapps |
patch, update |
— |
staticwebapp/deploy
Static Web App/Deploy — Trigger a deployment, or roll back to a previously deployed version.
- Data action: Yes
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
staticwebapp/readLogs
Static Web App/Read Logs — Stream a static web app's nginx logs.
- Data action: Yes
- Granted by: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
Boundaries
Catalogue module boundaries.
boundaries/create
Boundaries/Create — Create new boundaries.
- Data action: No
- Granted by: Platform Contributor, Platform Owner
boundaries/tenant/admin
Boundaries/Tenant Admin — Move a boundary to another tenant, new or existing. The boundary's people join the target tenant, which decides who they can see and how they sign in.
- Data action: No
- Granted by: Contributor, Owner, Platform Owner
boundaries/delete
Boundaries/Delete — Delete boundaries.
- Data action: No
- Granted by: Platform Owner
boundaries/list
Boundaries/List — List all boundaries across the platform.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
boundaries/read
Boundaries/Read — View a specific boundary.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
boundaries/manage
Boundaries/Manage — Update boundary configuration.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
boundaries/projections/read
Boundaries/Projections Read — View boundary projections in clusters.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
boundaries/projections/manage
Boundaries/Projections Manage — Attach or detach boundaries to clusters.
- Data action: No
- Granted by: Platform Contributor, Platform Owner
boundaries/projections/write
Boundaries/Projections Write — Write the Boundary custom resource into a projected cluster. Distinct from Manage, which decides *whether* a boundary is projected into a cluster; this maintains the resource that projection produces, and is what the boundary CR reconciler performs through the Kubernetes channel.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
boundaries/projections/delete
Boundaries/Projections Delete — Remove the Boundary custom resource from a cluster.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
boundaries/members/read
Boundaries/Members Read — View boundary membership and role assignments.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Reader
boundaries/members/manage
Boundaries/Members Manage — Add or remove members from a boundary.
- Data action: No
- Granted by: Owner, Platform Owner
boundaries/invitations/read
Boundaries/Invitations Read — View pending, accepted, revoked, and expired invitations on a boundary.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Reader
boundaries/invitations/create
Boundaries/Invitations Create — Send, revoke, and resend boundary invitations. Includes the implicit ability to read invitations on the boundary (a strict superset of boundaries/invitations/read).
- Data action: No
- Granted by: Owner, Platform Owner
boundaries/network/read
Boundaries/Network Read — See how a boundary's network is allowed to behave: which connections are permitted or blocked, why a connection was blocked, and the "can this reach that?" check. Reads the module's own projected policy set, never the cluster, so it carries no Kubernetes rules.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
boundaries/workloads/read
Boundaries/Workloads Read — View workloads (pods, services, configmaps) within a boundary.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Reader, Storage Operator, Storage Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
pods, services, configmaps |
get, list, watch |
— |
platform.stackship.se |
backuppolicies, restorerequests |
get, list, watch |
— |
crosslink/admin
Crosslink/Admin — Enable or disable cross-cluster connectivity for a boundary, choose the hub cluster, and rotate the boundary CA. Opting an individual resource in rides on that resource's own write permission, and reading topology rides on boundaries/read, so this is the only Crosslink-specific action.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
boundaries/workloads/manage
Boundaries/Workloads Manage — Create, update, and delete workloads within a boundary.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
pods, services, configmaps |
get, list, watch, create, update, patch, delete |
— |
apps |
deployments, statefulsets, replicasets |
get, list, watch, create, update, patch, delete |
— |
platform.stackship.se |
backuppolicies |
get, list, watch, create, update, patch, delete |
— |
platform.stackship.se |
restorerequests |
get, list, watch, create |
— |
boundaries/workloads/readLogs
Boundaries/Workloads Read Logs — Stream container logs from pods within a boundary's resource group. The kernel re-authorizes pod log stream calls under this action regardless of which module initiated them (e.g. apps build-logs, jobs runs, blueprints crates), so any role that needs to follow container logs through the portal needs this data action — the per-module `*/readLogs` actions cover the route gate, this one covers the kernel re-auth on the pod log stream.
- Data action: Yes
- Granted by: Apps Operator, Blueprint Reader, Blueprints Operator, Contributor, Databases Operator, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
pods/log |
get, list |
— |
Boundaries (Data Plane)
Catalogue module boundariesData.
pods/exec
Pods/Exec — Open an exec session into a pod.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
pods/exec |
create |
— |
pods/portForward
Pods/Port Forward — Open a port-forward tunnel to a pod.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
pods/portforward |
create |
— |
pods/attach
Pods/Attach — Attach to a running container in a pod.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
pods/attach |
create |
— |
pods/log
Pods/Log — Read log output from a pod.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
pods/log |
get |
— |
secrets/readSecretData
Secrets/Read Secret Data — Read the actual secret payload from a Kubernetes Secret.
- Data action: Yes
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
secrets |
get |
— |
Resource Groups
Catalogue module resource-groups.
resourcegroups/read
Resource Groups/Read — List and view resource groups.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
namespaces |
get, list, watch |
— |
resourcegroups/write
Resource Groups/Write — Create resource groups and their Kubernetes namespaces.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
namespaces |
get, list, watch, create, update, patch |
— |
resourcegroups/delete
Resource Groups/Delete — Delete resource groups and their Kubernetes namespaces.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
"" |
namespaces |
get, list, watch, delete |
— |
Sentinel
Catalogue module sentinel.
sentinel/read
Sentinel/Read — List and view security analysis jobs, findings, alerts, and resource configurations.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
sentinel/write
Sentinel/Write — Update finding status and manage resource-specific Sentinel configurations.
- Data action: No
- Granted by: Apps Operator, Blueprints Operator, Contributor, Databases Operator, Functions Operator, Jobs Operator, Owner, Platform Contributor, Platform Owner, Storage Operator
sentinel/admin
Sentinel/Admin — Read cluster-wide (platform-scoped) sentinel findings.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Monitoring
Catalogue module monitoring.
monitoring/platform/read
Monitoring/Platform/Read — Read cluster-wide CPU, memory and storage health and platform-scoped alerts. Root-scoped: cluster health belongs to no boundary, so a boundary-scoped grant must never reach it.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
monitoring/platform/alerts/write
Monitoring/Platform/Alerts/Write — Raise and clear a platform-scoped alert on behalf of another platform component. Root-scoped, and separate from the read because the roles that hold monitoring/platform/read are read-only platform roles. Held by module service accounts through Platform Alert Publisher, by no human role.
- Data action: No
- Granted by: Contributor, Owner, Platform Alert Publisher, Platform Contributor, Platform Owner
monitoring/read
Monitoring/Read — View resource metrics, alerts, and monitoring dashboards.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
Compliance
Catalogue module compliance.
compliance/read
Compliance/Read — View compliance framework dashboards (GDPR, NIS2, ISO 27001) and aggregated control status. No backend endpoints today — the action gates the portal page; Platform Reader / Owner pick it up via the `*/read` wildcard.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Policies
Catalogue module policies.
policies/read
Policies/Read — List and view the policies in force in a boundary.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
policies |
get, list, watch |
— |
policies/write
Policies/Write — Create, update, and delete policies within a boundary. Granted at boundary scope to Platform Owner, Platform Contributor, Boundary Owner, and Boundary Contributor.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
policies |
create, update, patch, delete |
— |
S3 Storage
Catalogue module s3.
s3storageaccounts/read
StorageAccounts/Read — List and view S3 storage accounts, capacity, and usage.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, watch |
— |
s3storageaccounts/write
StorageAccounts/Write — Create or update S3 storage accounts and their endpoint configuration.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, watch, create, update, patch |
— |
s3storageaccounts/delete
StorageAccounts/Delete — Delete S3 storage accounts. Honours the spec.storage.retainOnDelete flag for the underlying PVC.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
delete |
— |
s3storageaccounts/admin
StorageAccounts/Admin — Toggle administrative settings (allowS3ApiBucketLifecycle, retainOnDelete) on an existing account.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, watch, patch, update |
— |
s3buckets/read
S3/Buckets/Read — List and view buckets within an S3 storage account.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, watch |
— |
s3buckets/write
S3/Buckets/Write — Create buckets within an S3 storage account (portal path AND S3 API path).
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, patch |
— |
s3buckets/delete
S3/Buckets/Delete — Delete buckets within an S3 storage account.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, patch |
— |
s3objects/read
S3/Objects/Read — Read objects via SigV4-authorized GetObject, HeadObject, ListObjectsV2, and ListParts.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
s3objects/write
S3/Objects/Write — Write objects via SigV4-authorized PutObject, CopyObject, and multipart upload.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3objects/delete
S3/Objects/Delete — Delete objects via SigV4-authorized DeleteObject and DeleteObjects (batch).
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3accesskeys/read
S3/AccessKeys/Read — List and view S3 access keys (never includes the SecretAccessKey).
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
s3accesskeys/write
S3/AccessKeys/Write — Issue, update, or rotate S3 access keys. The SecretAccessKey is returned exactly once on issuance.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3accesskeys/delete
S3/AccessKeys/Delete — Revoke (delete) S3 access keys.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3sts/issue
S3/STS/Issue — Mint short-lived STS sessions (900-43200s) for an S3 storage account.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3/audit/read
S3/Audit/Read — Read per-operation S3 data-plane audit events for a storage account.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
Registry
Catalogue module registry.
registry/audit/read
Registry/Audit/Read — Query the registry audit log (push, pull and delete events) and view retention sweep history.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
registry/retention/manage
Registry/Retention/Manage — Trigger a registry retention sweep on demand.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Lifecycle
Catalogue module lifecycle.
lifecycle/view
Lifecycle/View — View the component registry, releases, rollout plans, and rollout status.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
componentrollouts |
get, list, watch |
— |
lifecycle/plan
Lifecycle/Plan — Create and validate rollout plans.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
componentrollouts |
get, list, watch |
— |
lifecycle/execute
Lifecycle/Execute — Execute, pause, and resume rollouts.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
componentrollouts |
get, list, watch, create, update, patch |
— |
lifecycle/rollback
Lifecycle/Rollback — Initiate rollbacks (re-targets each component's previous image; blocked past a contract boundary).
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
Also projected into Kubernetes RBAC for principals holding it:
| API group | Resources | Verbs | Names |
|---|---|---|---|
platform.stackship.se |
componentrollouts |
get, list, watch, create, update, patch |
— |
lifecycle/install
Lifecycle/Install — Install new platform components discovered on the release feed (provisioning runs inside the lifecycle module — no ComponentRollout CR involved).
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
lifecycle/backupsManage
Lifecycle/Backups Manage — Change the platform's backup target and daily backup schedule (the target change runs as a dependency rollout of Velero; the module's own account performs the writes, so no caller-side Kubernetes rule is needed).
- Data action: No
- Granted by: Contributor, Owner, Platform Owner
Search
Catalogue module search.
search/read
Search/Read — Execute searches across resources within a boundary.
- Data action: No
- Granted by: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Deployment Token Broker, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, LLM Gateway Consumer, Owner, Platform Alert Publisher, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
RBAC
Catalogue module rbac.
rbac/projector/apply
Rbac/Projector Apply — Apply the platform's own RBAC to every cluster, acting as the caller. Decides who may ask; each cluster's API server decides what they may actually write, against their own bearer — so holding this without the underlying Kubernetes rights gets a refusal from the cluster rather than an escalation.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
rbac/projector/read
Rbac/Projector Read — Read the RBAC manifest a cluster must have before the platform can project IAM into it — the projector ServiceAccount, the permission ceiling derived from this catalogue, and the binding between them. Reading it is reading the upper bound on what the platform can ever grant in that cluster, which is what an operator inspects before applying it.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
rbac/members/read
Members/Read — List members of a tenant.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
rbac/members/write
Members/Write — Invite, remove, and manage tenant members.
- Data action: No
- Granted by: Owner, Platform Owner
rbac/members/admin
Members/Admin — Cross-tenant membership management — platform-admin only.
- Data action: No
- Granted by: Owner, Platform Owner
rbac/idpBindings/admin
IdpBindings/Admin — Manage tenant→Keycloak-IdP-alias bindings — platform-admin only.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner
rbac/boundaryTrusts/admin
BoundaryTrusts/Admin — Create and remove trusts that let one boundary's workload identities be granted roles in another, including across tenants — platform-admin only.
- Data action: No
- Granted by: Owner, Platform Owner
rbac/users/list
Users/List — Search all Keycloak realm users without the per-tenant filter. Granted to platform-level roles for cross-tenant administration; everyone else only sees principals already mirrored into TenantMembership for the tenant whose boundary they're operating in.
- Data action: No
- Granted by: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader