Skip to main content

Permissions

The full casbin permission catalog. Every permission gates one or more API endpoints + UI affordances. Roles (built-in or custom) are collections of these permissions.

How to read the table​

Each row is a (object, action) pair. The object names a resource class; the action names a verb against it. UI elements are described as buttons / drawer entries that won't render unless the user's role grants the permission for the active organization.

The matcher is (user, org_id, object, action) — every check runs in an org context. Super-admins bypass.

Org-scoped permissions​

objectactionWhat it gates
edge-instancescreate"Add Edge" button on Edge Instances page; backend rejects POST otherwise
edge-instancesreadEdge Instances list + detail; nodes tab; health tab; VM console (vm:console is folded into this read perm)
edge-instancesupdateEdit drawer save button
edge-instancesdeleteRemove action in row menu
edge-instancesread-healthHealth tab content (separate from list read so you can grant "see edges" without "see why they're broken")
helminstallInstall button on marketplace + reinstall
helmupgradeUpgrade drawer save
helmuninstallUninstall action
helmlist-releasesApplications page list + force-sync
helmstatusDetail page status tab
helmresourcesResources tab + view/edit YAML
registriescreate / read / update / deleteRegistry CRUD
registriesuploadPush artifacts (chart / image tar) into the registry
marketplacecreate / read / update / deleteMarketplace CRUD
marketplaceinstallInstall button (separate from helm:install so a role can browse marketplace + use direct helm but not "marketplace install" if you ever need that distinction; in practice both are usually granted together)
memberscreate / read / update / deleteOrg Members tab — invite, list, change role, remove
rolescreate / read / update / deleteOrg Roles tab — define + manage custom roles
orgupdateOrg settings (rename, etc.)
orgdeleteSoft-delete the org
audit-logsreadAudit Logs page
observabilityreadMetrics + logs tabs in release detail; PromQL test query
webhookscreate / read / update / deleteOrg Webhooks page
provisionerreadView provisioner-managed cluster lifecycle
provisionerprovisionProvision-new-cluster path in Add Edge
provisionermanageSSH keys + presets management
alarmscreate / read / update / deleteAlarms CRUD
velerocreate / read / update / deleteBackups + Restores
backup-locationscreate / read / update / deleteExternal S3 backup targets. Any of create / update / delete makes the Backup Locations tab appear on the Organizations page; update also gates the per-row Test action. Global locations (defined by the platform admin) are testable but never editable from an org.
vmaction / consoleVM start/stop/restart + VNC

Public-resource permissions (admin/super-admin only)​

These only surface in the casbin catalog when the active license carries the corresponding cap > 0:

objectgating cap
public-edges:*MaxPublicEdges > 0
public-registries:*MaxPublicRegistries > 0
public-marketplace:*MaxPublicMarketplacePackages > 0

If the cap is 0, the perms are filtered out of AvailablePermissions and the corresponding admin pages don't render — you can't grant a perm for a feature the license doesn't expose.

Built-in roles vs permissions​

Default mappings (your install may have customised these via Admin → Settings → Roles defaults):

RolePermissions
viewerAll read permissions
developerviewer + helm:*, registries:*, marketplace:* (excluding delete on marketplace by default), webhooks:*
operatordeveloper + alarms:*, velero:*, vm:*
adminoperator + members:*, roles:*, org:*

Adding a permission to a custom role​

Org → Roles → Add role → permission grid is grouped by object. Tick the actions you want; save.

A user assigned that role gets the permissions immediately on their next request — no logout needed.

Testing what a permission grants​

If you're unsure what a permission gates, the audit log usually helps. Take an action with a privileged role; observe which endpoints + UI buttons appeared. Then strip the permission from a custom role and try the same action — the difference is what the permission gates.

See also​