Skip to content
Stackship documentation Svenska

S3 storageUsers

Permissions

The actions that govern storage accounts, buckets, access keys and temporary credentials, and the roles that hold them.

These actions govern what people and service accounts may do with storage accounts on the platform — in the portal and through the platform's API. They do not limit S3 requests: any valid temporary credential has full access to its account's buckets and objects, and any valid access key to those of every storage account in its boundary — see What a key can do.

Actions

Action Allows
s3storageaccounts/read See storage accounts, their configuration and usage
s3storageaccounts/write Create storage accounts and change their settings. Includes s3storageaccounts/delete
s3storageaccounts/delete Delete storage accounts
s3storageaccounts/admin Not checked by anything today; the Advanced settings are saved with s3storageaccounts/write
s3buckets/read See buckets
s3buckets/write Create buckets. Includes s3buckets/delete
s3buckets/delete Delete buckets
s3accesskeys/read See access keys, never their secrets
s3accesskeys/write Issue access keys and disable them. Includes s3accesskeys/delete
s3accesskeys/delete Delete access keys
s3sts/issue Get temporary credentials; needed to browse buckets in the portal
s3/audit/read Read the account's audit log
s3objects/read, s3objects/write, s3objects/delete Not applied today: S3 requests are not checked against them

Roles

Role See Create, change, delete accounts Buckets Access keys Browse buckets Audit log
Reader Yes No See See No No
Storage Reader Yes No See See No No
Storage Operator Yes Yes Create, delete Issue, disable, delete Yes No
Contributor, Owner Yes Yes Create, delete Issue, disable, delete Yes Yes

Assign a role on a boundary or a resource group — see Role assignments. The storage account list under S3 Storage needs s3storageaccounts/read on the boundary itself; with a role held only in a resource group, that list does not load.

Warning

Role assignments on a single storage account, made on its Access Control tab, are not applied: the platform's API checks storage account, bucket, access key and temporary-credential requests against the resource group or the boundary, so a role held only on the account grants nothing there. Assignments on a single bucket are not applied either — see Bucket permissions.