Permissions
The actions that govern static web apps, and the roles that hold them.
Actions
| Action | Allows |
|---|---|
staticwebapp/read |
See static web apps, their configuration and their deployments |
staticwebapp/write |
Create sites and change their source, directory, routing, domain and replicas; Stop, Start and restart. Includes staticwebapp/delete |
staticwebapp/delete |
Delete sites |
staticwebapp/scale |
Change the number of replicas with stsh swa scale |
staticwebapp/deploy |
Deploy and Serve this deployment |
staticwebapp/readLogs |
Read deploy logs and the web server's logs |
staticwebapp/deploy and staticwebapp/readLogs are data actions: a role only grants them when
it lists them as such.
Important
staticwebapp/deploygates only Deploy and Serve this deployment. It does not stop a holder ofstaticwebapp/writefrom shipping new content: saving a new source, branch, commit or directory deploys the site, and restart (stsh swa restart, or the API's restart action) packages it again from its source.staticwebapp/writecan also setreplicasin an update, withoutstaticwebapp/scale.
Creating a site in the portal also needs kernel/deployments/read, to list the boundary's
deployment sources. Streaming logs also needs boundaries/workloads/read and
boundaries/workloads/readLogs, which the platform checks when it reads the site's pods; every
role below that can read logs has them.
Roles
| Role | See | Create, change, stop, start, delete | Scale | Deploy, serve an earlier deployment | Logs |
|---|---|---|---|---|---|
| Reader | Yes | No | No | No | Yes |
| Apps Reader | Yes | No | No | No | No |
| Apps Operator | Yes | Yes | Yes | Yes | Yes |
| Contributor, Owner | Yes | Yes | Yes | Yes | Yes |
Assign a role on a boundary, a resource group or a single site; a site's own assignments are on its Access Control tab. See Role assignments.