Hoppa till innehållet
Stackship-dokumentation English

ÅtkomstkontrollAnvändareMaskinöversatt

IAM-åtgärder

Alla IAM-åtgärder per modul, med de inbyggda roller som ger dem.

Genererad från plattformens RBAC-katalog — redigera inte.

Kernel

Katalogmodul kernel.

kernel/clusters/read

Clusters/Read — List and view registered clusters.

kernel/clusters/write

Clusters/Write — Create, update, or delete cluster registrations.

kernel/platform/read

Platform/Read — View the platform component map, component status, and cluster topology. Root-scoped: what the platform is made of belongs to no boundary, so a boundary-scoped grant must never reach it.

kernel/platform/diagnose

Platform/Diagnose — Inspect a platform component's pods, events and stall reasons, and the platform database's internals. Platform Owner only — pod names, restart counts, event messages and connection state are operator-grade detail a read-only platform role has no reason to hold.

kernel/deployments/read

Deployments/Read — Read deployment sources, installations, repositories, branches, and credential health.

kernel/deployments/write

Deployments/Write — Create deployment sources and ensure webhooks.

kernel/deployments/delete

Deployments/Delete — Delete a deployment source and revoke its credentials.

kernel/deployments/token

Deployments/Token — Mint a short-lived source-repo access token for cloning.

kernel/activity/read

Activity/Read — List activity records and read list-configuration metadata.

kernel/activity/write

Activity/Write — Append activity records for audit logging.

kernel/k8sChannel/read

Kubernetes Channel/Read — List and get Stackship custom resources via the in-cluster Kubernetes channel.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se * get, list, watch —

kernel/k8sChannel/write

Kubernetes Channel/Write — Create, update, or delete Stackship custom resources via the in-cluster Kubernetes channel.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se * get, list, watch, create, update, patch, delete —

kernel/k8sChannel/readSecretMetadata

Kubernetes Channel/Read Secret Metadata — List and read Kubernetes Secret objects with all material removed by the channel. Grants names, labels and annotations — never data or stringData. Granted to no built-in role by default: at boundary scope this enumerates tenant-chosen Secret names across every boundary, which is a capability to hand out deliberately rather than a read to fold into a broad role.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" secrets get, list, watch —

kernel/k8sChannel/readNamespacedRbac

Kubernetes Channel/Read Namespaced RBAC — List and read Kubernetes Roles and RoleBindings in a boundary's namespaces, so a permissions failure can be explained with the permissions that actually existed. Read-only — writing a permission object is how something grants itself more access, and that stays reconciler-only. Cluster-wide RBAC is not served at all: a ClusterRoleBinding listing maps the whole cluster's privilege graph.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
rbac.authorization.k8s.io roles, rolebindings get, list, watch —

kernel/k8sChannel/readNamespaceDiagnostics

Kubernetes Channel/Read Namespace Diagnostics — List and read Events, LimitRanges and ResourceQuotas — what the cluster said happened, and the limits it happened under. Read-only: raising your own ResourceQuota or LimitRange is a privilege change wearing a diagnostic's clothes.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" events, limitranges, resourcequotas get, list, watch —

kernel/operations/read

Operations/Read — List, view, and dismiss operations.

kernel/resourceStatus/read

ResourceStatus/Read — Subscribe to real-time resource status updates over SignalR.

kernel/crates/read

Crates/Read — Subscribe to real-time crate status updates over SignalR.

kernel/crates/readLogs

Crates/ReadLogs — Stream crate logs over SignalR.

kernel/crates/exec

Crates/Exec — Open an interactive terminal session against a crate.

kernel/emailTemplates/manage

EmailTemplates/Manage — List, edit, preview, test-send, restore versions, and reset email templates used for transactional emails. Root-scoped, Platform Owner only.

kernel/emailSettings/manage

EmailSettings/Manage — View and edit SMTP / email delivery settings (host, port, credentials, from address). Root-scoped, Platform Owner only.

kernel/mcpSettings/manage

McpSettings/Manage — Turn the MCP interface for AI clients on and off. Root-scoped, Platform Owner only — the switch decides whether an AI client can reach this installation's API at all.

kernel/telemetrySettings/manage

TelemetrySettings/Manage — View and edit where the platform exports its own errors, metrics and traces. Root-scoped, Platform Owner only — it decides whether platform telemetry leaves the perimeter at all, and to whom.

kernel/docsFeedback/export

DocsFeedback/Export — Download the docs feedback kept on this platform ("Did this help?" answers and docs searches that found nothing), to send to Stackship by hand. Root-scoped; held by the platform-wide admin roles through `*/*`. Not a read, so Platform Reader's `*/read` does not reach it: comments are free text. Submitting feedback needs no action.

kernel/llmGateways/read

LlmGateways/Read — List and view registered LLM gateways, their models and health. Never the API key. Root-scoped.

kernel/llmGateways/write

LlmGateways/Write — Register, change, verify and set the default LLM gateway, including replacing or removing its API key. Root-scoped.

kernel/llmGateways/delete

LlmGateways/Delete — Delete a registered LLM gateway. Root-scoped.

kernel/llmGateways/resolve

LlmGateways/Resolve — Resolve an LLM gateway over the channel — its URL, enabled models and API key. The reply is a credential, so platform services hold this through the LLM Gateway Consumer role rather than by module identity.

Apps

Katalogmodul apps.

apps/read

Apps/Read — List and view apps, deployment slots, runtimes, metrics.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se apps get, list, watch —

apps/write

Apps/Write — Create or update apps and their configuration.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se apps get, list, watch, create, update, patch —

apps/delete

Apps/Delete — Delete apps.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se apps delete —

apps/scale

Apps/Scale — Scale an app's replica count or compute plan.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se apps patch, update —

apps/readLogs

Apps/Read Logs — Stream build and runtime logs for an app.

apps/readFiles

Apps/Read Files — List and download files on an app's persistent disk (/data), through the file-agent sidecar. Reaching the disk goes through pods/exec, and Kubernetes cannot scope pods/exec to one container or one argv — so this is exec-equivalent at the cluster layer and is deliberately NOT granted to reader tiers. See meta/docs/specs/pvc-file-browser.md §4.1.

apps/writeFiles

Apps/Write Files — Upload, move, rename and delete files on an app's persistent disk. Same exec-equivalence as apps/readFiles, plus the ability to change what the app reads on its next start.

Blueprints

Katalogmodul blueprints.

blueprints/read

Blueprints/Read — List and view blueprint templates in the catalog.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se blueprints get, list, watch —

blueprints/templates/write

Blueprints/Templates/Write — Create, update or delete boundary-scoped blueprint templates. Safe to grant because a template renders into a container-instance spec and can only express what the public API can express — it cannot describe a privileged pod, a hostPath or an RBAC object, because the document shape has nowhere to put them. Built-in templates are seeded from disk and are not writable through this action.

Functions

Katalogmodul functions.

functions/read

Functions/Read — List and view functions, namespaces, runtimes, metrics.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se functions, functionnamespaces get, list, watch —

functions/write

Functions/Write — Create or update functions and function namespaces.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se functions, functionnamespaces get, list, watch, create, update, patch —

functions/delete

Functions/Delete — Delete functions or function namespaces.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se functions, functionnamespaces delete —

functions/scale

Functions/Scale — Adjust a function's compute plan or concurrency.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se functions, functionnamespaces patch, update —

functions/readLogs

Functions/Read Logs — Stream build and runtime logs for a function.

Jobs

Katalogmodul jobs.

jobs/read

Jobs/Read — List and view jobs.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
batch jobs get, list, watch —

jobs/write

Jobs/Write — Create or update jobs.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
batch jobs get, list, watch, create, update, patch —

jobs/delete

Jobs/Delete — Delete jobs.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
batch jobs delete, deletecollection —

jobs/readLogs

Jobs/Read Logs — Stream logs from job pods.

Managed Identities

Katalogmodul managedIdentity.

managedidentities/read

Managed Identities/Read — List and view managed identities.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
identity.stackship.se managedidentities get, list, watch —

managedidentities/write

Managed Identities/Write — Create or update managed identities.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
identity.stackship.se managedidentities get, list, watch, create, update, patch —

managedidentities/delete

Managed Identities/Delete — Delete managed identities.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
identity.stackship.se managedidentities delete, deletecollection —

managedidentities/readSecrets

Managed Identities/Read Tokens — Issue or read tokens for a managed identity.

Secrets

Katalogmodul secrets.

secretvault/read

Secret Vault/Read — View and list secret vaults.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se secretvaults get, list, watch —

secretvault/write

Secret Vault/Write — Create or update secret vaults.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se secretvaults get, list, watch, create, update, patch —

secretvault/delete

Secret Vault/Delete — Delete secret vaults.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se secretvaults delete —

secretvault/readSecrets

Secret Vault/Read Secrets — Read secret values (connection strings, passwords) from a vault.

secretvault/writeSecrets

Secret Vault/Write Secrets — Create, update, or rotate secrets inside a vault.

Databases — Postgres

Katalogmodul databasesPostgres.

postgrescluster/read

Postgres Cluster/Read — View and list Postgres clusters.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
postgresql.cnpg.io clusters get, list, watch —

postgrescluster/write

Postgres Cluster/Write — Create or update Postgres clusters.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
postgresql.cnpg.io clusters get, list, watch, create, update, patch —

postgrescluster/delete

Postgres Cluster/Delete — Delete Postgres clusters.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
postgresql.cnpg.io clusters delete, deletecollection —

postgrescluster/scale

Postgres Cluster/Scale — Scale a Postgres cluster's replica count or compute plan.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
postgresql.cnpg.io clusters patch, update —

postgrescluster/createSnapshot

Postgres Cluster/Create Snapshot — Create a Velero backup snapshot of a Postgres cluster.

postgrescluster/restoreSnapshot

Postgres Cluster/Restore Snapshot — Restore a Postgres cluster from a snapshot.

postgrescluster/deleteSnapshot

Postgres Cluster/Delete Snapshot — Delete a Postgres cluster snapshot.

postgrescluster/readSecrets

Postgres Cluster/Read Secrets — Read connection strings and passwords for a Postgres cluster.

postgrescluster/writeSecrets

Postgres Cluster/Write Secrets — Rotate or update Postgres cluster credentials.

postgrescluster/dataRead

Postgres Cluster/Data Read — Browse rows via the structured row-browser endpoints.

postgrescluster/dataWrite

Postgres Cluster/Data Write — Insert, update, or delete rows via the structured row-browser endpoints.

postgrescluster/queryExecute

Postgres Cluster/Query Execute — Run read-only SQL (SELECT, EXPLAIN without ANALYZE) in the editor.

postgrescluster/queryExecuteWrite

Postgres Cluster/Query Execute Write — Run mutating SQL (INSERT/UPDATE/DELETE/MERGE, SELECT FOR UPDATE, LOCK) in the editor.

postgrescluster/schemaRead

Postgres Cluster/Schema Read — List schemas, tables, columns, and indexes.

postgrescluster/schemaWrite

Postgres Cluster/Schema Write — Create or alter database objects (CREATE TABLE/INDEX/VIEW, ALTER TABLE, VACUUM, REINDEX).

postgrescluster/schemaDrop

Postgres Cluster/Schema Drop — Drop or truncate database objects. Should be JIT-gated by default.

  • Dataåtgärd: Ja
  • Ges av: ingen inbyggd roll

Databases — SQL Server

Katalogmodul databasesSqlServer.

sqlservercluster/read

SQL Server/Read — View and list SQL Server instances.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se sqlservers get, list, watch —

sqlservercluster/write

SQL Server/Write — Create or update SQL Server instances; start, stop, and restart.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se sqlservers get, list, watch, create, update, patch —

sqlservercluster/delete

SQL Server/Delete — Delete SQL Server instances.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se sqlservers delete —

sqlservercluster/scale

SQL Server/Scale — Scale a SQL Server instance's compute plan or storage.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se sqlservers patch, update —

sqlservercluster/createSnapshot

SQL Server/Create Snapshot — Create a Velero backup snapshot of a SQL Server instance.

sqlservercluster/restoreSnapshot

SQL Server/Restore Snapshot — Restore a SQL Server instance from a snapshot.

sqlservercluster/deleteSnapshot

SQL Server/Delete Snapshot — Delete a SQL Server instance snapshot.

sqlservercluster/readSecrets

SQL Server/Read Secrets — Read connection strings and the SA password for a SQL Server instance.

sqlservercluster/writeSecrets

SQL Server/Write Secrets — Rotate or update SQL Server instance credentials.

sqlservercluster/manageLicense

SQL Server/Manage License — Set or rotate the product key for paid (Standard/Enterprise) editions.

sqlservercluster/dataRead

SQL Server/Data Read — Browse rows via the structured row-browser endpoints.

sqlservercluster/dataWrite

SQL Server/Data Write — Insert, update, or delete rows via the structured row-browser endpoints.

sqlservercluster/queryExecute

SQL Server/Query Execute — Run read-only T-SQL (SELECT, SET SHOWPLAN) in the editor.

sqlservercluster/queryExecuteWrite

SQL Server/Query Execute Write — Run mutating T-SQL (INSERT/UPDATE/DELETE/MERGE) in the editor.

sqlservercluster/schemaRead

SQL Server/Schema Read — List schemas, tables, columns, and indexes (sys.* / INFORMATION_SCHEMA).

sqlservercluster/schemaWrite

SQL Server/Schema Write — Create or alter database objects (CREATE/ALTER TABLE/INDEX/VIEW, sp_rename).

sqlservercluster/schemaDrop

SQL Server/Schema Drop — Drop or truncate database objects. Should be JIT-gated by default.

Databases — Qdrant

Katalogmodul databasesQdrant.

qdrantcluster/read

Qdrant Cluster/Read — View and list Qdrant clusters.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
qdrantoperator.io qdrantclusters get, list, watch —

qdrantcluster/write

Qdrant Cluster/Write — Create or update Qdrant clusters.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
qdrantoperator.io qdrantclusters get, list, watch, create, update, patch —

qdrantcluster/delete

Qdrant Cluster/Delete — Delete Qdrant clusters.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
qdrantoperator.io qdrantclusters delete, deletecollection —

qdrantcluster/scale

Qdrant Cluster/Scale — Scale a Qdrant cluster's replica count or compute plan.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
qdrantoperator.io qdrantclusters patch, update —

qdrantcluster/readSecrets

Qdrant Cluster/Read Secrets — Read API keys and connection information for a Qdrant cluster.

qdrantcluster/writeSecrets

Qdrant Cluster/Write Secrets — Rotate or update Qdrant cluster API keys.

Databases — Valkey

Katalogmodul databasesValkey.

valkey/read

Valkey/Read — View and list Valkey instances.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se valkeys get, list, watch —

valkey/write

Valkey/Write — Create or update Valkey instances.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se valkeys get, list, watch, create, update, patch —

valkey/delete

Valkey/Delete — Delete Valkey instances.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se valkeys delete —

valkey/readSecrets

Valkey/Read Secrets — Read the password and connection information for a Valkey instance.

valkey/writeSecrets

Valkey/Write Secrets — Rotate the password for a Valkey instance. Restarts the instance, which empties the cache.

Workflows

Katalogmodul workflows.

workflow/read

Workflow/Read — View and list workflows, including their graph and run history.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se workflows get, list, watch —

workflow/write

Workflow/Write — Create or update workflows and save new versions of their graph.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se workflows get, list, watch, create, update, patch —

workflow/delete

Workflow/Delete — Delete workflows.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se workflows delete —

workflow/trigger

Workflow/Trigger — Start a workflow run, and cancel or replay one. Runs execute with the workflow's own identity.

workflow/readStepIo

Workflow/Read Step Data — Read the inputs and outputs each node saw during a run. This is the data the workflow processed, verbatim.

  • Dataåtgärd: Ja
  • Ges av: ingen inbyggd roll

Container Instances

Katalogmodul containerInstances.

containerinstance/read

Container Instance/Read — View and list container instances.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se containerinstances get, list, watch —

containerinstance/write

Container Instance/Write — Create or update container instances (including start/stop/restart).

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se containerinstances get, list, watch, create, update, patch —

containerinstance/delete

Container Instance/Delete — Delete container instances.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se containerinstances delete —

containerinstance/scale

Container Instance/Scale — Scale a container instance's replica count.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se containerinstances patch, update —

containerinstance/createSnapshot

Container Instance/Create Snapshot — Take a snapshot of a container instance's persistent volumes.

containerinstance/restoreSnapshot

Container Instance/Restore Snapshot — Restore a container instance's volumes from a snapshot, in place.

containerinstance/deleteSnapshot

Container Instance/Delete Snapshot — Delete a container instance snapshot.

containerinstance/readLogs

Container Instance/Read Logs — Stream container log lines from the pods backing a container instance.

containerinstance/exec

Container Instance/Exec Terminal — Open an interactive terminal into a pod backing a container instance. Commands are audited. Deliberately NOT granted to reader tiers — a shell in the pod is write access to everything the workload can reach, whatever the CRD-level verbs say.

containerinstance/readFiles

Container Instance/Read Files — List and download files on a container instance's persistent volumes, through the file-agent sidecar. Reaching the volume goes through pods/exec, and Kubernetes cannot scope pods/exec to one container or one argv — so this is exec-equivalent at the cluster layer and, like containerinstance/exec, is deliberately NOT granted to reader tiers. See meta/docs/specs/pvc-file-browser.md §4.1.

containerinstance/writeFiles

Container Instance/Write Files — Upload, move, rename and delete files on a container instance's persistent volumes. Same exec-equivalence as containerinstance/readFiles, plus the ability to change what the workload reads on its next start.

containerinstance/access

Container Instance/Access — Browser access to a container instance's auth-guarded endpoints. Enforced by the instance-auth gateway via an ingress auth subrequest, not by an API route — no kubernetesRules needed. Replaces blueprints/instances/access.

Static Web Apps

Katalogmodul staticWebApps.

staticwebapp/read

Static Web App/Read — View and list static web apps, including deployment history.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se staticwebapps get, list, watch —

staticwebapp/write

Static Web App/Write — Create or update static web apps, including source, directory to serve and routing settings.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se staticwebapps get, list, watch, create, update, patch —

staticwebapp/delete

Static Web App/Delete — Delete static web apps.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se staticwebapps delete —

staticwebapp/scale

Static Web App/Scale — Scale a static web app's replica count.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se staticwebapps patch, update —

staticwebapp/deploy

Static Web App/Deploy — Trigger a deployment, or roll back to a previously deployed version.

staticwebapp/readLogs

Static Web App/Read Logs — Stream a static web app's nginx logs.

Boundaries

Katalogmodul boundaries.

boundaries/create

Boundaries/Create — Create new boundaries.

boundaries/tenant/admin

Boundaries/Tenant Admin — Move a boundary to another tenant, new or existing. The boundary's people join the target tenant, which decides who they can see and how they sign in.

boundaries/delete

Boundaries/Delete — Delete boundaries.

boundaries/list

Boundaries/List — List all boundaries across the platform.

boundaries/read

Boundaries/Read — View a specific boundary.

boundaries/manage

Boundaries/Manage — Update boundary configuration.

boundaries/projections/read

Boundaries/Projections Read — View boundary projections in clusters.

boundaries/projections/manage

Boundaries/Projections Manage — Attach or detach boundaries to clusters.

boundaries/projections/write

Boundaries/Projections Write — Write the Boundary custom resource into a projected cluster. Distinct from Manage, which decides *whether* a boundary is projected into a cluster; this maintains the resource that projection produces, and is what the boundary CR reconciler performs through the Kubernetes channel.

boundaries/projections/delete

Boundaries/Projections Delete — Remove the Boundary custom resource from a cluster.

boundaries/members/read

Boundaries/Members Read — View boundary membership and role assignments.

boundaries/members/manage

Boundaries/Members Manage — Add or remove members from a boundary.

boundaries/invitations/read

Boundaries/Invitations Read — View pending, accepted, revoked, and expired invitations on a boundary.

boundaries/invitations/create

Boundaries/Invitations Create — Send, revoke, and resend boundary invitations. Includes the implicit ability to read invitations on the boundary (a strict superset of boundaries/invitations/read).

boundaries/network/read

Boundaries/Network Read — See how a boundary's network is allowed to behave: which connections are permitted or blocked, why a connection was blocked, and the "can this reach that?" check. Reads the module's own projected policy set, never the cluster, so it carries no Kubernetes rules.

boundaries/workloads/read

Boundaries/Workloads Read — View workloads (pods, services, configmaps) within a boundary.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" pods, services, configmaps get, list, watch —
platform.stackship.se backuppolicies, restorerequests get, list, watch —

Crosslink/Admin — Enable or disable cross-cluster connectivity for a boundary, choose the hub cluster, and rotate the boundary CA. Opting an individual resource in rides on that resource's own write permission, and reading topology rides on boundaries/read, so this is the only Crosslink-specific action.

boundaries/workloads/manage

Boundaries/Workloads Manage — Create, update, and delete workloads within a boundary.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" pods, services, configmaps get, list, watch, create, update, patch, delete —
apps deployments, statefulsets, replicasets get, list, watch, create, update, patch, delete —
platform.stackship.se backuppolicies get, list, watch, create, update, patch, delete —
platform.stackship.se restorerequests get, list, watch, create —

boundaries/workloads/readLogs

Boundaries/Workloads Read Logs — Stream container logs from pods within a boundary's resource group. The kernel re-authorizes pod log stream calls under this action regardless of which module initiated them (e.g. apps build-logs, jobs runs, blueprints crates), so any role that needs to follow container logs through the portal needs this data action — the per-module `*/readLogs` actions cover the route gate, this one covers the kernel re-auth on the pod log stream.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" pods/log get, list —

Boundaries (Data Plane)

Katalogmodul boundariesData.

pods/exec

Pods/Exec — Open an exec session into a pod.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" pods/exec create —

pods/portForward

Pods/Port Forward — Open a port-forward tunnel to a pod.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" pods/portforward create —

pods/attach

Pods/Attach — Attach to a running container in a pod.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" pods/attach create —

pods/log

Pods/Log — Read log output from a pod.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" pods/log get —

secrets/readSecretData

Secrets/Read Secret Data — Read the actual secret payload from a Kubernetes Secret.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" secrets get —

Resource Groups

Katalogmodul resource-groups.

resourcegroups/read

Resource Groups/Read — List and view resource groups.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" namespaces get, list, watch —

resourcegroups/write

Resource Groups/Write — Create resource groups and their Kubernetes namespaces.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" namespaces get, list, watch, create, update, patch —

resourcegroups/delete

Resource Groups/Delete — Delete resource groups and their Kubernetes namespaces.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
"" namespaces get, list, watch, delete —

Sentinel

Katalogmodul sentinel.

sentinel/read

Sentinel/Read — List and view security analysis jobs, findings, alerts, and resource configurations.

sentinel/write

Sentinel/Write — Update finding status and manage resource-specific Sentinel configurations.

sentinel/admin

Sentinel/Admin — Read cluster-wide (platform-scoped) sentinel findings.

Monitoring

Katalogmodul monitoring.

monitoring/platform/read

Monitoring/Platform/Read — Read cluster-wide CPU, memory and storage health and platform-scoped alerts. Root-scoped: cluster health belongs to no boundary, so a boundary-scoped grant must never reach it.

monitoring/platform/alerts/write

Monitoring/Platform/Alerts/Write — Raise and clear a platform-scoped alert on behalf of another platform component. Root-scoped, and separate from the read because the roles that hold monitoring/platform/read are read-only platform roles. Held by module service accounts through Platform Alert Publisher, by no human role.

monitoring/read

Monitoring/Read — View resource metrics, alerts, and monitoring dashboards.

Compliance

Katalogmodul compliance.

compliance/read

Compliance/Read — View compliance framework dashboards (GDPR, NIS2, ISO 27001) and aggregated control status. No backend endpoints today — the action gates the portal page; Platform Reader / Owner pick it up via the `*/read` wildcard.

Policies

Katalogmodul policies.

policies/read

Policies/Read — List and view the policies in force in a boundary.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se policies get, list, watch —

policies/write

Policies/Write — Create, update, and delete policies within a boundary. Granted at boundary scope to Platform Owner, Platform Contributor, Boundary Owner, and Boundary Contributor.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se policies create, update, patch, delete —

S3 Storage

Katalogmodul s3.

s3storageaccounts/read

StorageAccounts/Read — List and view S3 storage accounts, capacity, and usage.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se s3storageaccounts get, list, watch —

s3storageaccounts/write

StorageAccounts/Write — Create or update S3 storage accounts and their endpoint configuration.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se s3storageaccounts get, list, watch, create, update, patch —

s3storageaccounts/delete

StorageAccounts/Delete — Delete S3 storage accounts. Honours the spec.storage.retainOnDelete flag for the underlying PVC.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se s3storageaccounts delete —

s3storageaccounts/admin

StorageAccounts/Admin — Toggle administrative settings (allowS3ApiBucketLifecycle, retainOnDelete) on an existing account.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se s3storageaccounts get, list, watch, patch, update —

s3buckets/read

S3/Buckets/Read — List and view buckets within an S3 storage account.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se s3storageaccounts get, list, watch —

s3buckets/write

S3/Buckets/Write — Create buckets within an S3 storage account (portal path AND S3 API path).

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se s3storageaccounts get, list, patch —

s3buckets/delete

S3/Buckets/Delete — Delete buckets within an S3 storage account.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se s3storageaccounts get, list, patch —

s3objects/read

S3/Objects/Read — Read objects via SigV4-authorized GetObject, HeadObject, ListObjectsV2, and ListParts.

s3objects/write

S3/Objects/Write — Write objects via SigV4-authorized PutObject, CopyObject, and multipart upload.

s3objects/delete

S3/Objects/Delete — Delete objects via SigV4-authorized DeleteObject and DeleteObjects (batch).

s3accesskeys/read

S3/AccessKeys/Read — List and view S3 access keys (never includes the SecretAccessKey).

s3accesskeys/write

S3/AccessKeys/Write — Issue, update, or rotate S3 access keys. The SecretAccessKey is returned exactly once on issuance.

s3accesskeys/delete

S3/AccessKeys/Delete — Revoke (delete) S3 access keys.

s3sts/issue

S3/STS/Issue — Mint short-lived STS sessions (900-43200s) for an S3 storage account.

s3/audit/read

S3/Audit/Read — Read per-operation S3 data-plane audit events for a storage account.

Registry

Katalogmodul registry.

registry/audit/read

Registry/Audit/Read — Query the registry audit log (push, pull and delete events) and view retention sweep history.

registry/retention/manage

Registry/Retention/Manage — Trigger a registry retention sweep on demand.

Lifecycle

Katalogmodul lifecycle.

lifecycle/view

Lifecycle/View — View the component registry, releases, rollout plans, and rollout status.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se componentrollouts get, list, watch —

lifecycle/plan

Lifecycle/Plan — Create and validate rollout plans.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se componentrollouts get, list, watch —

lifecycle/execute

Lifecycle/Execute — Execute, pause, and resume rollouts.

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se componentrollouts get, list, watch, create, update, patch —

lifecycle/rollback

Lifecycle/Rollback — Initiate rollbacks (re-targets each component's previous image; blocked past a contract boundary).

Projiceras också till Kubernetes RBAC för principaler som har den:

API-grupp Resurser Verb Namn
platform.stackship.se componentrollouts get, list, watch, create, update, patch —

lifecycle/install

Lifecycle/Install — Install new platform components discovered on the release feed (provisioning runs inside the lifecycle module — no ComponentRollout CR involved).

lifecycle/backupsManage

Lifecycle/Backups Manage — Change the platform's backup target and daily backup schedule (the target change runs as a dependency rollout of Velero; the module's own account performs the writes, so no caller-side Kubernetes rule is needed).

Katalogmodul search.

search/read

Search/Read — Execute searches across resources within a boundary.

RBAC

Katalogmodul rbac.

rbac/projector/apply

Rbac/Projector Apply — Apply the platform's own RBAC to every cluster, acting as the caller. Decides who may ask; each cluster's API server decides what they may actually write, against their own bearer — so holding this without the underlying Kubernetes rights gets a refusal from the cluster rather than an escalation.

rbac/projector/read

Rbac/Projector Read — Read the RBAC manifest a cluster must have before the platform can project IAM into it — the projector ServiceAccount, the permission ceiling derived from this catalogue, and the binding between them. Reading it is reading the upper bound on what the platform can ever grant in that cluster, which is what an operator inspects before applying it.

rbac/members/read

Members/Read — List members of a tenant.

rbac/members/write

Members/Write — Invite, remove, and manage tenant members.

rbac/members/admin

Members/Admin — Cross-tenant membership management — platform-admin only.

rbac/idpBindings/admin

IdpBindings/Admin — Manage tenant→Keycloak-IdP-alias bindings — platform-admin only.

rbac/boundaryTrusts/admin

BoundaryTrusts/Admin — Create and remove trusts that let one boundary's workload identities be granted roles in another, including across tenants — platform-admin only.

rbac/users/list

Users/List — Search all Keycloak realm users without the per-tenant filter. Granted to platform-level roles for cross-tenant administration; everyone else only sees principals already mirrored into TenantMembership for the tenant whose boundary they're operating in.