IAM-åtgärder
Alla IAM-åtgärder per modul, med de inbyggda roller som ger dem.
Genererad från plattformens RBAC-katalog — redigera inte.
Kernel
Katalogmodul kernel.
kernel/clusters/read
Clusters/Read — List and view registered clusters.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/clusters/write
Clusters/Write — Create, update, or delete cluster registrations.
- Dataåtgärd: Nej
- Ges av: Platform Owner
kernel/platform/read
Platform/Read — View the platform component map, component status, and cluster topology. Root-scoped: what the platform is made of belongs to no boundary, so a boundary-scoped grant must never reach it.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
kernel/platform/diagnose
Platform/Diagnose — Inspect a platform component's pods, events and stall reasons, and the platform database's internals. Platform Owner only — pod names, restart counts, event messages and connection state are operator-grade detail a read-only platform role has no reason to hold.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Owner
kernel/deployments/read
Deployments/Read — Read deployment sources, installations, repositories, branches, and credential health.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprints Operator, Contributor, Functions Operator, Owner, Platform Contributor, Platform Owner
kernel/deployments/write
Deployments/Write — Create deployment sources and ensure webhooks.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/deployments/delete
Deployments/Delete — Delete a deployment source and revoke its credentials.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/deployments/token
Deployments/Token — Mint a short-lived source-repo access token for cloning.
- Dataåtgärd: Nej
- Ges av: Contributor, Deployment Token Broker, Owner, Platform Contributor, Platform Owner
kernel/activity/read
Activity/Read — List activity records and read list-configuration metadata.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
kernel/activity/write
Activity/Write — Append activity records for audit logging.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Deployment Token Broker, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Alert Publisher, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
kernel/k8sChannel/read
Kubernetes Channel/Read — List and get Stackship custom resources via the in-cluster Kubernetes channel.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
* |
get, list, watch |
— |
kernel/k8sChannel/write
Kubernetes Channel/Write — Create, update, or delete Stackship custom resources via the in-cluster Kubernetes channel.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
* |
get, list, watch, create, update, patch, delete |
— |
kernel/k8sChannel/readSecretMetadata
Kubernetes Channel/Read Secret Metadata — List and read Kubernetes Secret objects with all material removed by the channel. Grants names, labels and annotations — never data or stringData. Granted to no built-in role by default: at boundary scope this enumerates tenant-chosen Secret names across every boundary, which is a capability to hand out deliberately rather than a read to fold into a broad role.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
secrets |
get, list, watch |
— |
kernel/k8sChannel/readNamespacedRbac
Kubernetes Channel/Read Namespaced RBAC — List and read Kubernetes Roles and RoleBindings in a boundary's namespaces, so a permissions failure can be explained with the permissions that actually existed. Read-only — writing a permission object is how something grants itself more access, and that stays reconciler-only. Cluster-wide RBAC is not served at all: a ClusterRoleBinding listing maps the whole cluster's privilege graph.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
rbac.authorization.k8s.io |
roles, rolebindings |
get, list, watch |
— |
kernel/k8sChannel/readNamespaceDiagnostics
Kubernetes Channel/Read Namespace Diagnostics — List and read Events, LimitRanges and ResourceQuotas — what the cluster said happened, and the limits it happened under. Read-only: raising your own ResourceQuota or LimitRange is a privilege change wearing a diagnostic's clothes.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
events, limitranges, resourcequotas |
get, list, watch |
— |
kernel/operations/read
Operations/Read — List, view, and dismiss operations.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
kernel/resourceStatus/read
ResourceStatus/Read — Subscribe to real-time resource status updates over SignalR.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
kernel/crates/read
Crates/Read — Subscribe to real-time crate status updates over SignalR.
- Dataåtgärd: Nej
- Ges av: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
kernel/crates/readLogs
Crates/ReadLogs — Stream crate logs over SignalR.
- Dataåtgärd: Ja
- Ges av: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
kernel/crates/exec
Crates/Exec — Open an interactive terminal session against a crate.
- Dataåtgärd: Ja
- Ges av: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
kernel/emailTemplates/manage
EmailTemplates/Manage — List, edit, preview, test-send, restore versions, and reset email templates used for transactional emails. Root-scoped, Platform Owner only.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/emailSettings/manage
EmailSettings/Manage — View and edit SMTP / email delivery settings (host, port, credentials, from address). Root-scoped, Platform Owner only.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/mcpSettings/manage
McpSettings/Manage — Turn the MCP interface for AI clients on and off. Root-scoped, Platform Owner only — the switch decides whether an AI client can reach this installation's API at all.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/telemetrySettings/manage
TelemetrySettings/Manage — View and edit where the platform exports its own errors, metrics and traces. Root-scoped, Platform Owner only — it decides whether platform telemetry leaves the perimeter at all, and to whom.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/docsFeedback/export
DocsFeedback/Export — Download the docs feedback kept on this platform ("Did this help?" answers and docs searches that found nothing), to send to Stackship by hand. Root-scoped; held by the platform-wide admin roles through `*/*`. Not a read, so Platform Reader's `*/read` does not reach it: comments are free text. Submitting feedback needs no action.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/llmGateways/read
LlmGateways/Read — List and view registered LLM gateways, their models and health. Never the API key. Root-scoped.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
kernel/llmGateways/write
LlmGateways/Write — Register, change, verify and set the default LLM gateway, including replacing or removing its API key. Root-scoped.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/llmGateways/delete
LlmGateways/Delete — Delete a registered LLM gateway. Root-scoped.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
kernel/llmGateways/resolve
LlmGateways/Resolve — Resolve an LLM gateway over the channel — its URL, enabled models and API key. The reply is a credential, so platform services hold this through the LLM Gateway Consumer role rather than by module identity.
- Dataåtgärd: Nej
- Ges av: Contributor, LLM Gateway Consumer, Owner, Platform Contributor, Platform Owner
Apps
Katalogmodul apps.
apps/read
Apps/Read — List and view apps, deployment slots, runtimes, metrics.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
apps |
get, list, watch |
— |
apps/write
Apps/Write — Create or update apps and their configuration.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
apps |
get, list, watch, create, update, patch |
— |
apps/delete
Apps/Delete — Delete apps.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
apps |
delete |
— |
apps/scale
Apps/Scale — Scale an app's replica count or compute plan.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
apps |
patch, update |
— |
apps/readLogs
Apps/Read Logs — Stream build and runtime logs for an app.
- Dataåtgärd: Ja
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
apps/readFiles
Apps/Read Files — List and download files on an app's persistent disk (/data), through the file-agent sidecar. Reaching the disk goes through pods/exec, and Kubernetes cannot scope pods/exec to one container or one argv — so this is exec-equivalent at the cluster layer and is deliberately NOT granted to reader tiers. See meta/docs/specs/pvc-file-browser.md §4.1.
- Dataåtgärd: Ja
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
apps/writeFiles
Apps/Write Files — Upload, move, rename and delete files on an app's persistent disk. Same exec-equivalence as apps/readFiles, plus the ability to change what the app reads on its next start.
- Dataåtgärd: Ja
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Blueprints
Katalogmodul blueprints.
blueprints/read
Blueprints/Read — List and view blueprint templates in the catalog.
- Dataåtgärd: Nej
- Ges av: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
blueprints |
get, list, watch |
— |
blueprints/templates/write
Blueprints/Templates/Write — Create, update or delete boundary-scoped blueprint templates. Safe to grant because a template renders into a container-instance spec and can only express what the public API can express — it cannot describe a privileged pod, a hostPath or an RBAC object, because the document shape has nowhere to put them. Built-in templates are seeded from disk and are not writable through this action.
- Dataåtgärd: Nej
- Ges av: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
Functions
Katalogmodul functions.
functions/read
Functions/Read — List and view functions, namespaces, runtimes, metrics.
- Dataåtgärd: Nej
- Ges av: Contributor, Functions Operator, Functions Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
functions, functionnamespaces |
get, list, watch |
— |
functions/write
Functions/Write — Create or update functions and function namespaces.
- Dataåtgärd: Nej
- Ges av: Contributor, Functions Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
functions, functionnamespaces |
get, list, watch, create, update, patch |
— |
functions/delete
Functions/Delete — Delete functions or function namespaces.
- Dataåtgärd: Nej
- Ges av: Contributor, Functions Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
functions, functionnamespaces |
delete |
— |
functions/scale
Functions/Scale — Adjust a function's compute plan or concurrency.
- Dataåtgärd: Nej
- Ges av: Contributor, Functions Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
functions, functionnamespaces |
patch, update |
— |
functions/readLogs
Functions/Read Logs — Stream build and runtime logs for a function.
- Dataåtgärd: Ja
- Ges av: Contributor, Functions Operator, Functions Reader, Owner, Platform Contributor, Platform Owner, Reader
Jobs
Katalogmodul jobs.
jobs/read
Jobs/Read — List and view jobs.
- Dataåtgärd: Nej
- Ges av: Contributor, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
batch |
jobs |
get, list, watch |
— |
jobs/write
Jobs/Write — Create or update jobs.
- Dataåtgärd: Nej
- Ges av: Contributor, Jobs Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
batch |
jobs |
get, list, watch, create, update, patch |
— |
jobs/delete
Jobs/Delete — Delete jobs.
- Dataåtgärd: Nej
- Ges av: Contributor, Jobs Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
batch |
jobs |
delete, deletecollection |
— |
jobs/readLogs
Jobs/Read Logs — Stream logs from job pods.
- Dataåtgärd: Ja
- Ges av: Contributor, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Reader
Managed Identities
Katalogmodul managedIdentity.
managedidentities/read
Managed Identities/Read — List and view managed identities.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
identity.stackship.se |
managedidentities |
get, list, watch |
— |
managedidentities/write
Managed Identities/Write — Create or update managed identities.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
identity.stackship.se |
managedidentities |
get, list, watch, create, update, patch |
— |
managedidentities/delete
Managed Identities/Delete — Delete managed identities.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
identity.stackship.se |
managedidentities |
delete, deletecollection |
— |
managedidentities/readSecrets
Managed Identities/Read Tokens — Issue or read tokens for a managed identity.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Secrets
Katalogmodul secrets.
secretvault/read
Secret Vault/Read — View and list secret vaults.
- Dataåtgärd: Nej
- Ges av: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
secretvaults |
get, list, watch |
— |
secretvault/write
Secret Vault/Write — Create or update secret vaults.
- Dataåtgärd: Nej
- Ges av: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Secrets Writer
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
secretvaults |
get, list, watch, create, update, patch |
— |
secretvault/delete
Secret Vault/Delete — Delete secret vaults.
- Dataåtgärd: Nej
- Ges av: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Secrets Writer
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
secretvaults |
delete |
— |
secretvault/readSecrets
Secret Vault/Read Secrets — Read secret values (connection strings, passwords) from a vault.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Secrets Reader, Secrets Writer
secretvault/writeSecrets
Secret Vault/Write Secrets — Create, update, or rotate secrets inside a vault.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Secrets Writer
Databases — Postgres
Katalogmodul databasesPostgres.
postgrescluster/read
Postgres Cluster/Read — View and list Postgres clusters.
- Dataåtgärd: Nej
- Ges av: Contributor, Database Explorer, Databases Operator, Databases Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
postgresql.cnpg.io |
clusters |
get, list, watch |
— |
postgrescluster/write
Postgres Cluster/Write — Create or update Postgres clusters.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
postgresql.cnpg.io |
clusters |
get, list, watch, create, update, patch |
— |
postgrescluster/delete
Postgres Cluster/Delete — Delete Postgres clusters.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
postgresql.cnpg.io |
clusters |
delete, deletecollection |
— |
postgrescluster/scale
Postgres Cluster/Scale — Scale a Postgres cluster's replica count or compute plan.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
postgresql.cnpg.io |
clusters |
patch, update |
— |
postgrescluster/createSnapshot
Postgres Cluster/Create Snapshot — Create a Velero backup snapshot of a Postgres cluster.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/restoreSnapshot
Postgres Cluster/Restore Snapshot — Restore a Postgres cluster from a snapshot.
- Dataåtgärd: Nej
- Ges av: Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/deleteSnapshot
Postgres Cluster/Delete Snapshot — Delete a Postgres cluster snapshot.
- Dataåtgärd: Nej
- Ges av: Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/readSecrets
Postgres Cluster/Read Secrets — Read connection strings and passwords for a Postgres cluster.
- Dataåtgärd: Ja
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/writeSecrets
Postgres Cluster/Write Secrets — Rotate or update Postgres cluster credentials.
- Dataåtgärd: Ja
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
postgrescluster/dataRead
Postgres Cluster/Data Read — Browse rows via the structured row-browser endpoints.
- Dataåtgärd: Ja
- Ges av: Database Explorer
postgrescluster/dataWrite
Postgres Cluster/Data Write — Insert, update, or delete rows via the structured row-browser endpoints.
- Dataåtgärd: Ja
- Ges av: Database Explorer
postgrescluster/queryExecute
Postgres Cluster/Query Execute — Run read-only SQL (SELECT, EXPLAIN without ANALYZE) in the editor.
- Dataåtgärd: Ja
- Ges av: Database Explorer
postgrescluster/queryExecuteWrite
Postgres Cluster/Query Execute Write — Run mutating SQL (INSERT/UPDATE/DELETE/MERGE, SELECT FOR UPDATE, LOCK) in the editor.
- Dataåtgärd: Ja
- Ges av: Database Explorer
postgrescluster/schemaRead
Postgres Cluster/Schema Read — List schemas, tables, columns, and indexes.
- Dataåtgärd: Ja
- Ges av: Database Explorer
postgrescluster/schemaWrite
Postgres Cluster/Schema Write — Create or alter database objects (CREATE TABLE/INDEX/VIEW, ALTER TABLE, VACUUM, REINDEX).
- Dataåtgärd: Ja
- Ges av: Database Explorer
postgrescluster/schemaDrop
Postgres Cluster/Schema Drop — Drop or truncate database objects. Should be JIT-gated by default.
- Dataåtgärd: Ja
- Ges av: ingen inbyggd roll
Databases — SQL Server
Katalogmodul databasesSqlServer.
sqlservercluster/read
SQL Server/Read — View and list SQL Server instances.
- Dataåtgärd: Nej
- Ges av: Contributor, Database Explorer, Databases Operator, Databases Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
sqlservers |
get, list, watch |
— |
sqlservercluster/write
SQL Server/Write — Create or update SQL Server instances; start, stop, and restart.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
sqlservers |
get, list, watch, create, update, patch |
— |
sqlservercluster/delete
SQL Server/Delete — Delete SQL Server instances.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
sqlservers |
delete |
— |
sqlservercluster/scale
SQL Server/Scale — Scale a SQL Server instance's compute plan or storage.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
sqlservers |
patch, update |
— |
sqlservercluster/createSnapshot
SQL Server/Create Snapshot — Create a Velero backup snapshot of a SQL Server instance.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/restoreSnapshot
SQL Server/Restore Snapshot — Restore a SQL Server instance from a snapshot.
- Dataåtgärd: Nej
- Ges av: Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/deleteSnapshot
SQL Server/Delete Snapshot — Delete a SQL Server instance snapshot.
- Dataåtgärd: Nej
- Ges av: Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/readSecrets
SQL Server/Read Secrets — Read connection strings and the SA password for a SQL Server instance.
- Dataåtgärd: Ja
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/writeSecrets
SQL Server/Write Secrets — Rotate or update SQL Server instance credentials.
- Dataåtgärd: Ja
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/manageLicense
SQL Server/Manage License — Set or rotate the product key for paid (Standard/Enterprise) editions.
- Dataåtgärd: Ja
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
sqlservercluster/dataRead
SQL Server/Data Read — Browse rows via the structured row-browser endpoints.
- Dataåtgärd: Ja
- Ges av: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/dataWrite
SQL Server/Data Write — Insert, update, or delete rows via the structured row-browser endpoints.
- Dataåtgärd: Ja
- Ges av: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/queryExecute
SQL Server/Query Execute — Run read-only T-SQL (SELECT, SET SHOWPLAN) in the editor.
- Dataåtgärd: Ja
- Ges av: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/queryExecuteWrite
SQL Server/Query Execute Write — Run mutating T-SQL (INSERT/UPDATE/DELETE/MERGE) in the editor.
- Dataåtgärd: Ja
- Ges av: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/schemaRead
SQL Server/Schema Read — List schemas, tables, columns, and indexes (sys.* / INFORMATION_SCHEMA).
- Dataåtgärd: Ja
- Ges av: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/schemaWrite
SQL Server/Schema Write — Create or alter database objects (CREATE/ALTER TABLE/INDEX/VIEW, sp_rename).
- Dataåtgärd: Ja
- Ges av: Contributor, Database Explorer, Owner, Platform Contributor, Platform Owner
sqlservercluster/schemaDrop
SQL Server/Schema Drop — Drop or truncate database objects. Should be JIT-gated by default.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Databases — Qdrant
Katalogmodul databasesQdrant.
qdrantcluster/read
Qdrant Cluster/Read — View and list Qdrant clusters.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Databases Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
qdrantoperator.io |
qdrantclusters |
get, list, watch |
— |
qdrantcluster/write
Qdrant Cluster/Write — Create or update Qdrant clusters.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
qdrantoperator.io |
qdrantclusters |
get, list, watch, create, update, patch |
— |
qdrantcluster/delete
Qdrant Cluster/Delete — Delete Qdrant clusters.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
qdrantoperator.io |
qdrantclusters |
delete, deletecollection |
— |
qdrantcluster/scale
Qdrant Cluster/Scale — Scale a Qdrant cluster's replica count or compute plan.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
qdrantoperator.io |
qdrantclusters |
patch, update |
— |
qdrantcluster/readSecrets
Qdrant Cluster/Read Secrets — Read API keys and connection information for a Qdrant cluster.
- Dataåtgärd: Ja
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
qdrantcluster/writeSecrets
Qdrant Cluster/Write Secrets — Rotate or update Qdrant cluster API keys.
- Dataåtgärd: Ja
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Databases — Valkey
Katalogmodul databasesValkey.
valkey/read
Valkey/Read — View and list Valkey instances.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Databases Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
valkeys |
get, list, watch |
— |
valkey/write
Valkey/Write — Create or update Valkey instances.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
valkeys |
get, list, watch, create, update, patch |
— |
valkey/delete
Valkey/Delete — Delete Valkey instances.
- Dataåtgärd: Nej
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
valkeys |
delete |
— |
valkey/readSecrets
Valkey/Read Secrets — Read the password and connection information for a Valkey instance.
- Dataåtgärd: Ja
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
valkey/writeSecrets
Valkey/Write Secrets — Rotate the password for a Valkey instance. Restarts the instance, which empties the cache.
- Dataåtgärd: Ja
- Ges av: Contributor, Databases Operator, Owner, Platform Contributor, Platform Owner
Workflows
Katalogmodul workflows.
workflow/read
Workflow/Read — View and list workflows, including their graph and run history.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
workflows |
get, list, watch |
— |
workflow/write
Workflow/Write — Create or update workflows and save new versions of their graph.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
workflows |
get, list, watch, create, update, patch |
— |
workflow/delete
Workflow/Delete — Delete workflows.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
workflows |
delete |
— |
workflow/trigger
Workflow/Trigger — Start a workflow run, and cancel or replay one. Runs execute with the workflow's own identity.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
workflow/readStepIo
Workflow/Read Step Data — Read the inputs and outputs each node saw during a run. This is the data the workflow processed, verbatim.
- Dataåtgärd: Ja
- Ges av: ingen inbyggd roll
Container Instances
Katalogmodul containerInstances.
containerinstance/read
Container Instance/Read — View and list container instances.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
containerinstances |
get, list, watch |
— |
containerinstance/write
Container Instance/Write — Create or update container instances (including start/stop/restart).
- Dataåtgärd: Nej
- Ges av: Apps Operator, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
containerinstances |
get, list, watch, create, update, patch |
— |
containerinstance/delete
Container Instance/Delete — Delete container instances.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
containerinstances |
delete |
— |
containerinstance/scale
Container Instance/Scale — Scale a container instance's replica count.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
containerinstances |
patch, update |
— |
containerinstance/createSnapshot
Container Instance/Create Snapshot — Take a snapshot of a container instance's persistent volumes.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
containerinstance/restoreSnapshot
Container Instance/Restore Snapshot — Restore a container instance's volumes from a snapshot, in place.
- Dataåtgärd: Nej
- Ges av: Owner, Platform Contributor, Platform Owner
containerinstance/deleteSnapshot
Container Instance/Delete Snapshot — Delete a container instance snapshot.
- Dataåtgärd: Nej
- Ges av: Owner, Platform Contributor, Platform Owner
containerinstance/readLogs
Container Instance/Read Logs — Stream container log lines from the pods backing a container instance.
- Dataåtgärd: Ja
- Ges av: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
containerinstance/exec
Container Instance/Exec Terminal — Open an interactive terminal into a pod backing a container instance. Commands are audited. Deliberately NOT granted to reader tiers — a shell in the pod is write access to everything the workload can reach, whatever the CRD-level verbs say.
- Dataåtgärd: Ja
- Ges av: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
containerinstance/readFiles
Container Instance/Read Files — List and download files on a container instance's persistent volumes, through the file-agent sidecar. Reaching the volume goes through pods/exec, and Kubernetes cannot scope pods/exec to one container or one argv — so this is exec-equivalent at the cluster layer and, like containerinstance/exec, is deliberately NOT granted to reader tiers. See meta/docs/specs/pvc-file-browser.md §4.1.
- Dataåtgärd: Ja
- Ges av: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
containerinstance/writeFiles
Container Instance/Write Files — Upload, move, rename and delete files on a container instance's persistent volumes. Same exec-equivalence as containerinstance/readFiles, plus the ability to change what the workload reads on its next start.
- Dataåtgärd: Ja
- Ges av: Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner
containerinstance/access
Container Instance/Access — Browser access to a container instance's auth-guarded endpoints. Enforced by the instance-auth gateway via an ingress auth subrequest, not by an API route — no kubernetesRules needed. Replaces blueprints/instances/access.
- Dataåtgärd: Ja
- Ges av: Blueprint Reader, Blueprints Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
Static Web Apps
Katalogmodul staticWebApps.
staticwebapp/read
Static Web App/Read — View and list static web apps, including deployment history.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
staticwebapps |
get, list, watch |
— |
staticwebapp/write
Static Web App/Write — Create or update static web apps, including source, directory to serve and routing settings.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
staticwebapps |
get, list, watch, create, update, patch |
— |
staticwebapp/delete
Static Web App/Delete — Delete static web apps.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
staticwebapps |
delete |
— |
staticwebapp/scale
Static Web App/Scale — Scale a static web app's replica count.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
staticwebapps |
patch, update |
— |
staticwebapp/deploy
Static Web App/Deploy — Trigger a deployment, or roll back to a previously deployed version.
- Dataåtgärd: Ja
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner
staticwebapp/readLogs
Static Web App/Read Logs — Stream a static web app's nginx logs.
- Dataåtgärd: Ja
- Ges av: Apps Operator, Contributor, Owner, Platform Contributor, Platform Owner, Reader
Boundaries
Katalogmodul boundaries.
boundaries/create
Boundaries/Create — Create new boundaries.
- Dataåtgärd: Nej
- Ges av: Platform Contributor, Platform Owner
boundaries/tenant/admin
Boundaries/Tenant Admin — Move a boundary to another tenant, new or existing. The boundary's people join the target tenant, which decides who they can see and how they sign in.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Owner
boundaries/delete
Boundaries/Delete — Delete boundaries.
- Dataåtgärd: Nej
- Ges av: Platform Owner
boundaries/list
Boundaries/List — List all boundaries across the platform.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
boundaries/read
Boundaries/Read — View a specific boundary.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
boundaries/manage
Boundaries/Manage — Update boundary configuration.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
boundaries/projections/read
Boundaries/Projections Read — View boundary projections in clusters.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
boundaries/projections/manage
Boundaries/Projections Manage — Attach or detach boundaries to clusters.
- Dataåtgärd: Nej
- Ges av: Platform Contributor, Platform Owner
boundaries/projections/write
Boundaries/Projections Write — Write the Boundary custom resource into a projected cluster. Distinct from Manage, which decides *whether* a boundary is projected into a cluster; this maintains the resource that projection produces, and is what the boundary CR reconciler performs through the Kubernetes channel.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
boundaries/projections/delete
Boundaries/Projections Delete — Remove the Boundary custom resource from a cluster.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
boundaries/members/read
Boundaries/Members Read — View boundary membership and role assignments.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Reader
boundaries/members/manage
Boundaries/Members Manage — Add or remove members from a boundary.
- Dataåtgärd: Nej
- Ges av: Owner, Platform Owner
boundaries/invitations/read
Boundaries/Invitations Read — View pending, accepted, revoked, and expired invitations on a boundary.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Reader
boundaries/invitations/create
Boundaries/Invitations Create — Send, revoke, and resend boundary invitations. Includes the implicit ability to read invitations on the boundary (a strict superset of boundaries/invitations/read).
- Dataåtgärd: Nej
- Ges av: Owner, Platform Owner
boundaries/network/read
Boundaries/Network Read — See how a boundary's network is allowed to behave: which connections are permitted or blocked, why a connection was blocked, and the "can this reach that?" check. Reads the module's own projected policy set, never the cluster, so it carries no Kubernetes rules.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
boundaries/workloads/read
Boundaries/Workloads Read — View workloads (pods, services, configmaps) within a boundary.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Reader, Storage Operator, Storage Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
pods, services, configmaps |
get, list, watch |
— |
platform.stackship.se |
backuppolicies, restorerequests |
get, list, watch |
— |
crosslink/admin
Crosslink/Admin — Enable or disable cross-cluster connectivity for a boundary, choose the hub cluster, and rotate the boundary CA. Opting an individual resource in rides on that resource's own write permission, and reading topology rides on boundaries/read, so this is the only Crosslink-specific action.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
boundaries/workloads/manage
Boundaries/Workloads Manage — Create, update, and delete workloads within a boundary.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
pods, services, configmaps |
get, list, watch, create, update, patch, delete |
— |
apps |
deployments, statefulsets, replicasets |
get, list, watch, create, update, patch, delete |
— |
platform.stackship.se |
backuppolicies |
get, list, watch, create, update, patch, delete |
— |
platform.stackship.se |
restorerequests |
get, list, watch, create |
— |
boundaries/workloads/readLogs
Boundaries/Workloads Read Logs — Stream container logs from pods within a boundary's resource group. The kernel re-authorizes pod log stream calls under this action regardless of which module initiated them (e.g. apps build-logs, jobs runs, blueprints crates), so any role that needs to follow container logs through the portal needs this data action — the per-module `*/readLogs` actions cover the route gate, this one covers the kernel re-auth on the pod log stream.
- Dataåtgärd: Ja
- Ges av: Apps Operator, Blueprint Reader, Blueprints Operator, Contributor, Databases Operator, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
pods/log |
get, list |
— |
Boundaries (Data Plane)
Katalogmodul boundariesData.
pods/exec
Pods/Exec — Open an exec session into a pod.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
pods/exec |
create |
— |
pods/portForward
Pods/Port Forward — Open a port-forward tunnel to a pod.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
pods/portforward |
create |
— |
pods/attach
Pods/Attach — Attach to a running container in a pod.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
pods/attach |
create |
— |
pods/log
Pods/Log — Read log output from a pod.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
pods/log |
get |
— |
secrets/readSecretData
Secrets/Read Secret Data — Read the actual secret payload from a Kubernetes Secret.
- Dataåtgärd: Ja
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
secrets |
get |
— |
Resource Groups
Katalogmodul resource-groups.
resourcegroups/read
Resource Groups/Read — List and view resource groups.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
namespaces |
get, list, watch |
— |
resourcegroups/write
Resource Groups/Write — Create resource groups and their Kubernetes namespaces.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
namespaces |
get, list, watch, create, update, patch |
— |
resourcegroups/delete
Resource Groups/Delete — Delete resource groups and their Kubernetes namespaces.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
"" |
namespaces |
get, list, watch, delete |
— |
Sentinel
Katalogmodul sentinel.
sentinel/read
Sentinel/Read — List and view security analysis jobs, findings, alerts, and resource configurations.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
sentinel/write
Sentinel/Write — Update finding status and manage resource-specific Sentinel configurations.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Blueprints Operator, Contributor, Databases Operator, Functions Operator, Jobs Operator, Owner, Platform Contributor, Platform Owner, Storage Operator
sentinel/admin
Sentinel/Admin — Read cluster-wide (platform-scoped) sentinel findings.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Monitoring
Katalogmodul monitoring.
monitoring/platform/read
Monitoring/Platform/Read — Read cluster-wide CPU, memory and storage health and platform-scoped alerts. Root-scoped: cluster health belongs to no boundary, so a boundary-scoped grant must never reach it.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
monitoring/platform/alerts/write
Monitoring/Platform/Alerts/Write — Raise and clear a platform-scoped alert on behalf of another platform component. Root-scoped, and separate from the read because the roles that hold monitoring/platform/read are read-only platform roles. Held by module service accounts through Platform Alert Publisher, by no human role.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Alert Publisher, Platform Contributor, Platform Owner
monitoring/read
Monitoring/Read — View resource metrics, alerts, and monitoring dashboards.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
Compliance
Katalogmodul compliance.
compliance/read
Compliance/Read — View compliance framework dashboards (GDPR, NIS2, ISO 27001) and aggregated control status. No backend endpoints today — the action gates the portal page; Platform Reader / Owner pick it up via the `*/read` wildcard.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Policies
Katalogmodul policies.
policies/read
Policies/Read — List and view the policies in force in a boundary.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
policies |
get, list, watch |
— |
policies/write
Policies/Write — Create, update, and delete policies within a boundary. Granted at boundary scope to Platform Owner, Platform Contributor, Boundary Owner, and Boundary Contributor.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
policies |
create, update, patch, delete |
— |
S3 Storage
Katalogmodul s3.
s3storageaccounts/read
StorageAccounts/Read — List and view S3 storage accounts, capacity, and usage.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, watch |
— |
s3storageaccounts/write
StorageAccounts/Write — Create or update S3 storage accounts and their endpoint configuration.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, watch, create, update, patch |
— |
s3storageaccounts/delete
StorageAccounts/Delete — Delete S3 storage accounts. Honours the spec.storage.retainOnDelete flag for the underlying PVC.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
delete |
— |
s3storageaccounts/admin
StorageAccounts/Admin — Toggle administrative settings (allowS3ApiBucketLifecycle, retainOnDelete) on an existing account.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, watch, patch, update |
— |
s3buckets/read
S3/Buckets/Read — List and view buckets within an S3 storage account.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, watch |
— |
s3buckets/write
S3/Buckets/Write — Create buckets within an S3 storage account (portal path AND S3 API path).
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, patch |
— |
s3buckets/delete
S3/Buckets/Delete — Delete buckets within an S3 storage account.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
s3storageaccounts |
get, list, patch |
— |
s3objects/read
S3/Objects/Read — Read objects via SigV4-authorized GetObject, HeadObject, ListObjectsV2, and ListParts.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
s3objects/write
S3/Objects/Write — Write objects via SigV4-authorized PutObject, CopyObject, and multipart upload.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3objects/delete
S3/Objects/Delete — Delete objects via SigV4-authorized DeleteObject and DeleteObjects (batch).
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3accesskeys/read
S3/AccessKeys/Read — List and view S3 access keys (never includes the SecretAccessKey).
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader, Storage Operator, Storage Reader
s3accesskeys/write
S3/AccessKeys/Write — Issue, update, or rotate S3 access keys. The SecretAccessKey is returned exactly once on issuance.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3accesskeys/delete
S3/AccessKeys/Delete — Revoke (delete) S3 access keys.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3sts/issue
S3/STS/Issue — Mint short-lived STS sessions (900-43200s) for an S3 storage account.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Storage Operator
s3/audit/read
S3/Audit/Read — Read per-operation S3 data-plane audit events for a storage account.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
Registry
Katalogmodul registry.
registry/audit/read
Registry/Audit/Read — Query the registry audit log (push, pull and delete events) and view retention sweep history.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
registry/retention/manage
Registry/Retention/Manage — Trigger a registry retention sweep on demand.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Lifecycle
Katalogmodul lifecycle.
lifecycle/view
Lifecycle/View — View the component registry, releases, rollout plans, and rollout status.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
componentrollouts |
get, list, watch |
— |
lifecycle/plan
Lifecycle/Plan — Create and validate rollout plans.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
componentrollouts |
get, list, watch |
— |
lifecycle/execute
Lifecycle/Execute — Execute, pause, and resume rollouts.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
componentrollouts |
get, list, watch, create, update, patch |
— |
lifecycle/rollback
Lifecycle/Rollback — Initiate rollbacks (re-targets each component's previous image; blocked past a contract boundary).
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
Projiceras också till Kubernetes RBAC för principaler som har den:
| API-grupp | Resurser | Verb | Namn |
|---|---|---|---|
platform.stackship.se |
componentrollouts |
get, list, watch, create, update, patch |
— |
lifecycle/install
Lifecycle/Install — Install new platform components discovered on the release feed (provisioning runs inside the lifecycle module — no ComponentRollout CR involved).
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
lifecycle/backupsManage
Lifecycle/Backups Manage — Change the platform's backup target and daily backup schedule (the target change runs as a dependency rollout of Velero; the module's own account performs the writes, so no caller-side Kubernetes rule is needed).
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Owner
Search
Katalogmodul search.
search/read
Search/Read — Execute searches across resources within a boundary.
- Dataåtgärd: Nej
- Ges av: Apps Operator, Apps Reader, Blueprint Reader, Blueprints Operator, Contributor, Database Explorer, Databases Operator, Databases Reader, Deployment Token Broker, Functions Operator, Functions Reader, Jobs Operator, Jobs Reader, LLM Gateway Consumer, Owner, Platform Alert Publisher, Platform Contributor, Platform Owner, Platform Reader, Reader, Secrets Reader, Secrets Writer, Storage Operator, Storage Reader
RBAC
Katalogmodul rbac.
rbac/projector/apply
Rbac/Projector Apply — Apply the platform's own RBAC to every cluster, acting as the caller. Decides who may ask; each cluster's API server decides what they may actually write, against their own bearer — so holding this without the underlying Kubernetes rights gets a refusal from the cluster rather than an escalation.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
rbac/projector/read
Rbac/Projector Read — Read the RBAC manifest a cluster must have before the platform can project IAM into it — the projector ServiceAccount, the permission ceiling derived from this catalogue, and the binding between them. Reading it is reading the upper bound on what the platform can ever grant in that cluster, which is what an operator inspects before applying it.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
rbac/members/read
Members/Read — List members of a tenant.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader, Reader
rbac/members/write
Members/Write — Invite, remove, and manage tenant members.
- Dataåtgärd: Nej
- Ges av: Owner, Platform Owner
rbac/members/admin
Members/Admin — Cross-tenant membership management — platform-admin only.
- Dataåtgärd: Nej
- Ges av: Owner, Platform Owner
rbac/idpBindings/admin
IdpBindings/Admin — Manage tenant→Keycloak-IdP-alias bindings — platform-admin only.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner
rbac/boundaryTrusts/admin
BoundaryTrusts/Admin — Create and remove trusts that let one boundary's workload identities be granted roles in another, including across tenants — platform-admin only.
- Dataåtgärd: Nej
- Ges av: Owner, Platform Owner
rbac/users/list
Users/List — Search all Keycloak realm users without the per-tenant filter. Granted to platform-level roles for cross-tenant administration; everyone else only sees principals already mirrored into TenantMembership for the tenant whose boundary they're operating in.
- Dataåtgärd: Nej
- Ges av: Contributor, Owner, Platform Contributor, Platform Owner, Platform Reader