Permissions
The actions that govern the registry's audit log and retention sweep, and the roles that hold them.
Actions
| Action | Allows |
|---|---|
registry/audit/read |
Read the registry audit log, list retention runs and preview a sweep |
registry/retention/manage |
Start a retention sweep |
Both are checked at the platform root: the audit log and the sweep cover the whole registry, not one boundary, so a role assigned on a boundary or below does not grant them.
Roles
| Role, assigned at the platform root | Audit log, runs, preview | Start a sweep |
|---|---|---|
| Platform Reader | Yes | No |
| Platform Contributor | Yes | Yes |
| Platform Owner | Yes | Yes |
Pushing and pulling images is not governed by these actions: the platform issues registry credentials to its builds and to each boundary's namespaces itself — see Who can reach it.